sssd-kcm-2.5.1-2.el8 >  A `{U]q;\X?]Dft!a*!yڗwu'd ~9+rPj`~ֵ!cq%&k'nQ4% ]He-Ll!c,˵ T%8S'Lwzѿ?:1aX+TIIJDE~6ƸmW{1&|0l ޒҰn/`vR0JWxF+}h.TAܮȨ}h|ӛIG/0_Z 4դ/4o؀[vUP_谒jf%>R\%}I{ۨmR>WX-Ƨa\tP鍫Хdaee045cb8cbc8b70fd34439ea95575b451af5c07a0566eb40b3e9d65493224eddf808e4c9d8c1c68cd5c852bc5b104cf4524a82`{U]p#DPG>vMmmT79sju%j_lSb"@D/F,G-`F3IۊzTb\zdٲ_06~!)x/ms5Zf(cȦY2,݆D3DPc^s`ɩ9j$I k>+u&#OYRA y߰p d{s˟) O_zqGDpBn ?nd   B #@FMbt   ( w _H> @>>(89:dN>d?d@dGdHeIeLXe`Yep\e]e^f bgdieifi li"ti<uixviwl xlHylOmmmn Csssd-kcm2.5.12.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.` x86-01.mbox.centos.org8CentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxx86_64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi,%0EځAAA큤A큤` ` ` ` ` ` ` ` ` ` ` ` ` ` ` acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8b4e29a574d0d8fb18abdee833929707d2486eab2d2c21cf074496be2e7bf9daf1e289a1777d0d580c1f5213e35a73c7457b2de147632caeed0cbe205707183c3389e4ca0245464845ce87e767988ba701569d1b20a89f17568a89ce60af5dd1ea036de188ab955e9a19de9d4b88a7847b7f1e55d62aea8cd00d38f33abb38bd3353b5665e3885c8992b660d53347c387ec2c93e46b34b1fb21b55cdc2f4728fa0385c7131ae3ec2df4b609d6e76728881eb18e0fb6da0fce602def11fb16a872acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/lib64/sssd/libsss_secrets.so../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.5.1-2.el8.src.rpmconfig(sssd-kcm)libsss_secrets.so()(64bit)sssd-kcmsssd-kcm(x86-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.28)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcares.so.2()(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)libjansson.so.4()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_secrets.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.5.1-2.el83.0.4-14.6.0-14.0-15.2-12.5.1-2.el84.14.3`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh svuk2.5.1-2.el82.5.1-2.el82.5.1-2.el8 kcm_default_ccache.build-idde39eb9c833f606f80c47f297638ebd53f33e2b7e544e0d8a45502f2c1f427e5eb5e79da05db9d47sssd-kcm.servicesssd-kcm.socketlibsss_secrets.sosssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/de//usr/lib/.build-id/e5//usr/lib/systemd/system//usr/lib64/sssd//usr/libexec/sssd//usr/share/man/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=de39eb9c833f606f80c47f297638ebd53f33e2b7, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=e544e0d8a45502f2c1f427e5eb5e79da05db9d47, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)2PRR.R RR*R!RRRR"R/RRRRR R R#R%RR$R1R-RR&R+RR8R0R,R4RRRRRR.RR RR R RR2RRRRRR3R*R%R&R$R'R(R)R!RRRR"R/RRRRR R R#RR1R-RR+R RR8utf-83a7982e8d971abafecdb8c8e11ea76dbab6780c331c2bf7d10a1dff3120b296f?7zXZ !#,] b2u Q{LQ >#TKy%,D%b<$6ޯ:_^ca@K{,c[Ҭ 7JDv8 P!nAM#h#0a%F/;t)JgĿ҅OKM))x9Ў% k:iog|A].,D*ΦPxg# p!:-fP\VLW-K\15\/ӂ5Wրm,(jl 3UAo}NFupG]*r4Te8ەL\%̇H`b,7~Qcr=n57Gq~//S)[r՝Y/r3-9Pkt^u<%u]邇 /(%=ܽ[%U.56ඵUp8C6;\㋌m ?#QV$C``jj,.S Y\RtRL $ AHlRS.qWz ^T\4m0L.f;oYȗ80;*"| $7nəۣ}CZY?|gxs|ڸQP/Lz++K4biSȂϛjpK\rq?otwTE)?n7.fm5'߁|®K*Mkz)\&#@.t$0xDy-h48|!;I#>lOH[219@4+LߦFSKiWI$O?NN)5yLFkf8n9B  "41kJثEAvş]UO%2Es2W/ʄ2 m1Rv:"[jy~kk[ bh5.9Gb}K*ul5HQ0*(Øv"7h 8q 8{58\B(Ď~J̬N!aʰQ3Kkx>*O̞Œȸ?5V3)-Y$u 4h Fl`P> "7ɻU!QvۯKloc'@[e (^7 #qO3ѣw>I&nUb뚆DF[ᢆ.Bsޅ}#H{ P.DL|MH_l^0a- I„7 }6,ReVR-M3٭nr|G5lO3k-s*1oy~YWс 0reٝkEL9t aSac )6i\U91bvr3AZ],]gb)ɥ3)-'$*"brDHODut~@՞"Z JF.,>6ûs, ^(ISDLƆr~\e a\hXp9Nk)Og֔Hajo7c^TPe(K}Qt1E%p4ygͺ%r {tE]t˽ JR$U%?)%yܗ:!ьuW[B:. t5!S>AEqZ[EJT=0O w&,<~5ѕNbn.\P;Q,Ѫ8&;ˡ@YmIPݦFt [?0o4#j4|lJ}hoo5V$O%_>.Lz2(˒#_1Xcbs=?sFKD"A sd?C 'yX"lpoPyg=l. ۠Qh8]%ōM].|uOX4`58BfiUyU{l7nKCTV3 W$i8UZ;qZNK53\%pO%wO9ެ} 2񕮾d w䷪i|VM#Vgx43__uҍ.pO۬ZׯEa)b?3_f 6~?CѷIR37*1\5%Q3MOu5ⰻw>!5`ٖFAc%.ߡ6BhR>Ųt)ήZ7/ZۆOАOjrr(<'~jFSWgI^wU5{0ȱ|U㑤639-Y j@P>'蠠;BjAJgELo2b4}gdzχtрJn Zxl'[WղY7pQ(k .Au[+SQ.:|7粄86T&^HhUMKVTu]k)BBuN,F ib.h(XdZ7P9$ԸSٚtr9F&Bl G $U "Mlp$h;C, _0KN/)OL͇]f;wŌ)<$Ώfhv2V{+HQ.-5L/ZG#rs$MC"A93 bk`Be{tZtp~Tnsǁ?!.-{>D4?7YzDi$KHTxEҜ<9g=Kd0([eHWIG2F^m`Åqzɞ0xLO{S C u͕>=HRbI N}?\U_U[K+2!؃!*,٭&'"eJD-PqgaDj+8GVx#e=!F'?Da׀`7'jH_#l1EguχyBgIc{o JŏD6uï%/`mMmm'Ez{&f#G,jyV).q1drwmc.BpF6xg-SREETz[dVٕxh9qdce+= u   Y3ʕuN*_2\[yZ#CeM\5,>/d , #ns>ftd/Eq*<{Ʋ.ꮥLjS=6JX<Pȶ 4*Km&O :û e{&w/ZbfEo4!SM_AaG*:&U&19[Bv2J䍷J. [gĺCZkm`,g'_Nc'K}!@]3Y~_QZyY? 6.F:W)/Y+/̭xHm۷qL!xҫxQ~s4#$7J,( @V\~"`{`_A6wE-FMΏ) vVO94S o:oq^AL a[f(%C=*QWTIb?gTi)h8XY>j+ҭ:G. z#ԍ0A”%7-hȶlHjJ4>Ԑ#95b X|'u^=[TLS:easv+f4?u _LyA>a4wFP^n2i,?:2v)n[2>ąmL=i5w0vFyҨ7ޑb-B5=^mk$}ۙJ*t3 4 bN CnowrtnϮ-:OZټHP?l$,6`>Y{ R?x߶nӐ]xLea=%?߾.<;Ҍ 25zh*4X\uΎ7 S ȵI 2[kŐҙ1z :n̚am a`8YǩU>sYԊn|=!$`RgqXe~kz3e쬯qg+<{ElŁ 4{W?և/HX``F&дi=Ȍ'ɜx<4}cZ*:NA#U!X=\('.絘4d VA۲he,h|wihT,ښ L/@Un *0!AQrfxǒ <Dac>4)S +v>< ǪHU>Pn,I 0 : a'[¤hDߤ<#AWw=/{gsu2|~όjrWm39  `'i~pSܫb׿9wNXl@Q+MP? <Ï-L !EQEZϑψL%*oP/.Lw'FJjܛ!32=s+uBs;dd}i jQ6Ko6@+uy,Lu?͞ĐA5.V9 ,g{I W~ίbɞӡi:֠aq'F9dˉ| Ь5ݛhp$K2x2 &?$;a.3Jlt Cޡ"m*VM6Md\|IsJ X./eC@_Pf#D1[U/s CWfJ91X򭈋cSe1d7^NjO%Qkw)@b{NğQ?&L'%=h:*E?&c*z3gymf̒ ]B {_mL]dfSBf|ӭ`c]dl jӮT&S"?!󏞈˖;j[0a+)Q;aN 'x:\IjbjfG/gW)z׼ҲQ(n2olͼ`49:UR9c!ߟ!Gq8Ney{xy!J." c Jf5G !Tj^rņr)R-p^N>OR qM̦|/*XC60OqZ z1u;md7l31u QPPgI*]S-]!MAYU׈e,GcM5:p{΃MI-DOg!rg5ݧm`y"/>KDb] RIq-fcQ/˔m$9HK~3)?T+1&M-M7ȥ6xO=ftC`WáwEÜ35wm~9x-AߪJʹghn :0F d~`{N3('"9n3Ot1v-@ZBtUvCr7M Wwa靾H7eӕixL2zO CID-S!j(e i9wb40E>&>"0G9MYl +3_pxN1Qz;I̥t&AStvd̼ ao @X pMۖhϭ &U9blWiR."|FPp$3oh3,jB7=*R -O[I813JZw˻sO X̓!@c^- S$Fڢ;h=1:h3LS&";1 ?9$P9MB 0ՙ€cL_3'ېTRL!ؽJIנ蝑)MTFǬ<0wۅ봽׺{;ky0 tf\]LtIkeSfVScH7zލZ⧯n)fkX|F]sNܠv 7.yxU+2DyAw*T 6kPc1VȚ<~=:jLmy ;0[@H WB1C =&`nO/E'f>/%$g]iY}&%%J[ ~ W ȚG %T\QPTYnWBr,,~!Ob?3n$ѭ:k[GV'LTÄ<#bEq%H CI]2E%{tH VX[?:v{ZÝSf_RUgY35h4L fayu9n[smlu @'(V,BL*p4b]`--OvLArޱ&H ׇK/M.6)pGs/Ƌ4ؾ0 zH6 ILr W`ծeg$WkME.?UX@ 9p~}"327Mb ?M[hժ-\TL|wgd%n\8 OS_xCRhl;&ۦ,x5~Q)S2:+ a4a8Fh:3T+M:zx@<_ud2|SCʊAG HAd\/@),(N5C;LGb9"!\(]5՝5,RWvaJ=d%#){4$jnPsU<X8d1̊g.#3JiꨝIN_sQeeL{&5Y`ߦ8I*f&rbg&jG3}ɼi/ep vGɽsJ)Zt+2l}gls\Q llk}HU8=DvVam!ejo*:sg&Ag ?F668^`$)D́)hOlv*+vsYFkS9隠ZԮr1D@L{D\\929WN{ƽCm}_jFj$ܓ|܏w%v)O "gnc26vX.A.41dItNBi%Tm%C57 rRͲ(,Q7)*cCr)37hֻ6GzE~ sꬲ6tP'EnawlQ7HgwHK|Nwyj2zIXS\uCɫDWH$O8q@CCIA se>?EBOCu}"*s5MKoLSCg=Sc؀zd]n *(]UWmۭؑtup`ct!GGԞ;p}n ]ܥV+@$>o<,Uuf0hvZpo`oMe[KkTU&!Icw$I7=>ߵg ^^r$n󄮹YS0xQ] s#7>d[BYyh@lzd'Dm;#J#հ} D<hq|#QVe*P gybʛ2 -5p, Y"sB)UQzJkw}H i]%/!- Cq|ɨ/7L$ͿoJZ 1`Sn\V 2]aw}݀X 3CR>+r O_WsN0&%$5хÿ%:x f`z͜3y&Њ,,fU{L2B81 I8+! [28<`0X5fJ.pޒTQO4S6djCV@6&w9?zN@d:=Ȣ׏{BVop㎊0b+ o-֜F#ޠؠ|V ^ќOB~à %2e^77x}&O\xO5DFwp <iH'"ǝM< TБAJg^'t;I9}\8gJ.QǿW Uq7DGB SJp *A =zwI 'pMj ULW<TuBc͘]/͏}.o8 ∍8N!øG XbV~go<&$uSBH1iAT#]{#һQh瘢7>P{Lj<щ؄{)Y[ii)!.64ӗČ#vq:#zD Jή #۠ ~~7\8N'4O' Iؽ.jT=_tόҁx}+xcFsxYf(S<ħ]pu%}hnrakBi1nxEEL"-pc(Bb!W,ׇOYm!ȧF83O[wr OS8`lοB]Nɉ/5f`:[BssK8ўk x|Ms;q NUf?w-1Z˗K4FzK c3_y{r:W -_L?XV?}n2 $3O_]2IUX/~Czue5ŗ t(z0эlg=$lo0mjDr kȘy-[-9Ā Gʼא8\J\!V9X%1͊vO=mEȿ~|''~C[FTks Hlx%*q:Z!GKj@hd^<~0FvKLt!<1| ڇ"L{|3k35߇"N,K 2pΠ"$yFl-Cv/qoBhݢ<TlLH< EgYŬ#(qJW*DQ"6t7ݧ:5NJ"kn AVG&t;sEM:SJDPĨYܻ"K(͎ym>X. :T_N,jH˖* $ԗ(w'߂K`ޞ~"Y_ctUK u؜b7$cVX vNF(Y<MkYQ '63xC!;AP^܀GQ;YEqLu9Low0HinkY=U ~0YL}dy<Arq vOdi-Yb6@I~ϙTDD1VLsTSݖ Q~n/J &/"K5g؁epa{X$3?˦B fQԯmxb >vo'{l2θm^qa=_H)l=ılv]Fjۧ{(tw{QG~=1l2h+Vj.I6XY0 EItOSw3+)ҫZ>~tÛe;5Z~ҞC~ E+6IQ~wޅFQE^Zxx+,VH@[dr7#kA:aHMHZk85HiES ԰fɮ#𭙄|{ =Ih0giw8nN@@Q[u;`ʑ"`${Sh3iqaw?o]ϫ*id,$őlpju0TaX +-%ߣ!)m-αg_AԨNsMF ^׎P(bL>jNlnN.<9Yb ťav{Neb}XFꕠmSn"w .o_B:baoWHTGW,K8Ą}v71ѽo(Ck ruvK7<9eL IHAOt%zlcyA[J0[ B%K:[\4"eg>Z"Sw§Wo=w]i{ 1; Qs6"&M0V6{OVLLNC0^b]{``}Sob=,_}>pE9͘V[_%w͒ٯ4|pYS1rCьѳV҉]U7qJs||#Ы |H[q'ݼ7> Q9p 솣Q+uѠF? OX+~~T?`zR.oC[bɎ} `[rO,!`0h ١[WZl&<-)"8FzlLA b77 i-:GkK m/ DTTs&fs }cώBn"$@LlZu+

^  xzLfqQ'Y@|FU1͊R!MqtADqQh 7dN@`Fbß$G-|dҺp= r}Gx|[ sS@MI!zo- >3/-Ci3U$;-fe-L;6 $U m[(HPQ`Ya~A%)fHuV#T1I5=~d}o]N~uC;w~C&Ny&V?loޖ56|SCv ,$~obF"ǿWuAK|~Pabo#9#s 0ٽD /(Y,0S M@s~X-c UgM/c.ү?朝+qdR _"-U$P,_͕I1wjQSWUFy-bSD{z6*>f)$=ijC|1P6cX 7v}=Ɋ vs.Z䙛_|%AShϓ"#{ op$8߯X%Bֿq2>,Y1DȭoZiA@i:/ߜD1k%'5( M.ԪE-P[}&֠ 0n@ 3rFZTZI)^8*Wf̟pB?K?(J%c;8 I8a/ ugۓa2BJmT`]1(ۆmUhղr,7ˢ-y(v Ojnj zn!zRML'O(t4,{/}~١_MÖa1a_s6+]AǮ(9!i>iTسW{&߳<=0p}qH-._, ޱpCwU_p"wk#t2# E aNŮ)ڕ=F7,MOܩ$ Lr^+n Zl96l&tgo*_%0áXɪSIFPVa}ꑌj7ADD'$<')tG7qY-*!ksos] D}s>p}7kժ/Kݫ5;Ӱf MD+5xwkmkܵKtum;6Yr a8X&׿Ywp'ħwcDx gx&-6jf)V32D^,nש`!!5Tp3Bȹmt ?nOhmduW(~:.uQ/ 1L#Jw\q+*Ȟ^H6!wP~]Z#%['2HPBojSqVz bhDk ׅbݣ-WHKՊ@wך$xI)䳓Tl^uu0wC[8 A1~M ϰP;r^kc. XOB`[mhƮ("`y?ՋL$EU#$u_:oa!3VGM v0:= G0sA( 6$u^:aD 6G*@U97βsEHRa= SiC[#m/'FzAAaoK= :޻y@*Vw@q{p}ضXh^q FbfZu%׭!TKn_s s@Z\*B7 vދ$~%W- sCRI8fLupLQ+V;*&-rl8+y10|4^y &5( 0 K.T;i'|04|Yz[GB=l(_+ILGGubf?FIٵm䀍?}[hĺt ZlHGmK`Pȓ E?x'w%=:ki>6wvk͋,β{HFT7[sdRՃ=9 yѦn Aj,MwbVm{I /]s@E+C1c&#[q/!$sHV1PT>4 ASGy7&*!./@]!q, EgKie6J@T?TZP5I'e8S=(׻k)J"oEp;}N[x^ "L:]16K9A)_3;B|bI6)rdF#/1/Eڃf(D JhOʑPctjdP`ZP㭧R)_rǮj'%u4{K"{l,*B8tbXUne6Uϫ wҾ\![&pAZ>YD[; t}*{@e/+i{\_-cK?9d %^}ءx^c}COJpMdNԲgh$%ƓRjH1UʷGtSh_GBo}+1ԥ}SsTNjQ:7JL9rGT'(L|(k%ǸR/(ɀZos*suon@u4'{dANxҮznGTV1 [bpSCg-y۷ %H`H ߫™W~ݒYl# &7$rIrѾ["%iigV%Wο^𰋣UN4 y@xDg (2Jf< հjyY3CI: YF~v8.>u8 =XP6_*4 p-^~=R_r%ޱ"k,듳V.*>-OEKO1벍rppxSt>`{ssl$ĕV}'ox/f`NT9} Fo9 G$˃E$ IÕCA9BEŴ'ЍNkFC#L zxRzg@7^/ElW; ]Mta8nq7͊+V ̩5l{=GC,OvAYg;tw"(DLůzbyƟ:tۋ9B` BipR N#Bʫ^ t3=oa;2_QC&:R&uaa8>H޻iHi""lCFiGo{7px;s;;SE>c#Q9mZ.YZ5'Rce$r͵gz6;F{!4F>z`A_I_}ٝY.dX͸x{$s<B4uQUѬڪI)#!}up|nU 9V[ m#?o<\ᡯN>XL~XpQ$Jm'8h1Ucõd׸~Hg7s+߳8*sN,MNW 3KG&lUwZړoX+0!`K-ʎ5lu8D]@:?VK'CZ|)XTU|v t!D"^-P6B]Q1V~iZcQ ꥗+^x-5C~͍Zi*|0<~ ʻ~v- _vR9@.PgAj)Ǭ AJH)iHZc!8F q$q gh16X%mYm-+Sa'4j K,"'>w{:p͟_&b !zQ),QhJ̄P>ʚй]XMD ޔfX I#~4w>%5 b~g _Β̇?oz7mb` C)8t>$44p=[4)e.9m_P_ t]؛0*/7n ̏N[H:1T}a*uU TzcAG@=Qf1 "x5tGT(6I1ݓ9uٟ,e*ڒi$`VX9hi!;enWn@~8p#ʇPpKKfYMF܊Yfc VoFxYgp}QXFFM[j*~ |Am s{f|N9~wPr&X)\rT T`p떨OE{g?%Gy|}R@qx*C._#M 2}bș+thFJ-Xmv!|kr2ݪS6ԔŲ׀J䠜;fRTBvn(/?a(VТŢlC$*]?m6sStʔe=0hFi=ya_׷vlTp<.9+imb зVf 8Œ3c,cLQFP O9gBkc|iσE Țr|-(݅tpUG#<]>cԀ7,*2-f2yQQ KSF*0 (Ңw(;ϼWF·q6 IsEs2#а1@#0w;me ~|JvZД$=k3] ;e 16XH&m\BBڋvB6p1u!N0:oK9N'5wXoO(JWvY$F-,A<rA8aڪтm݄K˰/[J΅J[htSCvAkI!)u%zE%07aɲI ި2$iKaO&&AHt|PHXÿIN}9Q&9C/Ԁ)fB3Lf:EyyFgʴpFbX{ eVn4Q;kJG P$Si~ S2XIa&חv^gšL-jpwBTlMo˨P Z a3pA8HuI% tBT*<1RkIjJ ff>!%p7^Ю2+ u;{Mh3m:əvX8˓68K$۶[+}t b>Gyr(`P!4,0v 9ئ@Tu@`KVyaNQIe$LGK/0YL7'N>uh8Mצ:2ts0`Iuiy(Fɘ<8IzmJ]$HJYw &SLd#5Ɉ5 lg$\!0LZ'Al\:H޼pBV|YMƩ8 iIR+ɟ߱WG;p2v>P vl}.yʈ05O_?jT:M6Ua.27YGR_N9x q]% _A;ʲgcL:=!畳5pl |mFw58 eLCEM*boj> C o,p$ Y%2zơ}U c|.U n vd0>L6{kdԹnY`:nssWb™ 27D@D%vOUDwZTǴt4z0!j$j]e5_}}wd7^#zzXCp8IHPߐ)UOWv g^q AcCd4D#ƤTLI6O<ۄ7[807r>W]kLoYY=PvZH: Vp^Drt=ʔ=.S!#?C[Tא_qX5R ޳"CipA_î~(L&kF5 >6o Kаљm2o4qX,Gq&|sJ/OX9aTgϕ)m+PjCw8B!4)YOBbE~*إyw๬9yeG\Ug2ۊ%VoNrr'gbkL)e.Hmm&AM #_Q.gQ3O;#<4&rZd;ʻws{>Y œ M[,r;0TNJ hlX hctcޢe84?G#~*`U0d{!`T[y2H_(?j”4.& ax)p(S-S_9 pOzMovlgnI% đ:Fa_FXX8̃i]]#P QZިym!b|8fk=kZ۪\Ud[,n|BH'g]q͝5*%UJvI{03p DSG+;᫬F3vlSnyKW<>V\>Œ)X!Y-Z/Wi*K4vkQXy)dY9Gh>x )Wqjҥ ]XV E]5qIwo0ml -!)Ư0@5H!LO!}Ǽ鏌K $d7x*h,̀8i ei-$_c)Ebz1-ҖP N_,:TR wR*Ҥ{;nFiRlmBq>7¶M Sbhm=J9&iZ6uKǒD#%R!(.*ͫ}bl=nQHMA%ӯL |;:o}QSHt1 W5pރEd]Ӽ oo+b:ۂk $B&'қ5.m\-rfC\C VE0a`9P}9MBTrh(*v " <H1EX "JV`Q Th0GV uF-[Roy2"G*V1LyMOPlk\>[JD/V 0 .$fX{ý a/CPgbgoW>bs{IQQ&ߝ?$E{`G6n.0"׹R,G S*QоC2!>XaH+*V{:v31F9[X (*&2Πf: jm ɴAQΆESUJɢujHސmaGG읅M< ߂IB†W _$vT`슨!9 tuŤ+#SPNEiBŹM\qh-( ՁZ(OK,=,tf{"YJlz! Y>L$7f2遴ߐaX2Q V;(=RO[UA^<E[Ǽ^؉:-U 8G_jRajs_oCJglFYRnF<#@ߢϗ*h(u@vjlj/ge!;j[iu-1(gmI `Qui qx<\ l8ݐ-w}⮐~G-O5' #r|UDH|9_W_W߯ )sٛ+xP u+q賀12(V |8#sƎ,fptM_Smiۍ5P},emjK {ίGr{JlE!ﮏBEͩh.'W} j-]oUc5J!q4LԢ^qrȼsv ϐGԢ8qG5/u~M fNcN;J0A$Q&46#9KZvU8S bV $*XDz6N_4*YtڞQfn}Ѐ<"xݠ0`mP\rhe!SぞE"Gu@Z'Z^7#:mKƫxU$YWlIDD'Az2t_A,\rSϛ&zQ7FRJ$7=OmewxXC1@HsS;aelE%a;p\2hBY*2qG'kvγބjȳuCF/Hvvz|?֒W0у:+AW^;?9A4nlb +\︞zƤ?bI9>Duz];1.edW8DTQu?k|=xof #d=X"Xh՞\sJ\qC-C P'EHϘOM&:&l:IuWāf&hDș]\-s(asEMXn8CڄFf,K \h·2soXSrR$ ZXzDtc"QNz/V7 2s$zT3lQ5iy%i"[?O\fJ $opYg*'JU"]pƑbvjq 6KSM+ަ=iϞLmN|T[KC|v+l U⹺WS&IrtOS4wS5)bb;#.XL6Jƿ$oԭ>?:ae Z>(YLSĐQF/JmmA3D\d F41/ .4苘{"ط.<]wMX?>2hp;ypH~faH)ǡS@fjx:ВW(4Ӹi,}m2/Y`i UOwmȕD|=OVq8GJ~\^ύ n'Oۙ S)d*rZ>Pm}UM=c A9^.m9ZKcPJqϞIw8Ep _bGt,ݕYҪ/ $/2vu%`3\څ%PJ6@xi9øwkm)3}8%c!e!ldƁTZ_A{8L)*N IϮeEHvnj*`Ӭ!ЏBUl.4ni?zK~c[x[ ,rlBjB`:0e$n?zƸފ4Wήք-Pvb!7"mR.?M$6}J^}e\58`=4kQ@En_E4)#*aFb]A?Mآ#!%Rs ݩ\OGr/U#l93̴e|EƟ rezvxĿaӄ@]Me=cUMeΥiZ=Cqgr  Xg b8B$Bq`D - `:hQUZwUҜQ Up\M'ȶ dB^vpX4ʂ .qK#y{H(eNwo3cg|*r(Ah;EO 8}6vI@# ] YE2[L\>evRZ>TݷY1JAtS,"<,̅G=“PPW k y΄Z8D wS̒H /RX qj"Sy&a_(W`['j׺ZL=0AɁLM3LǕE2A7\E$FK7Wi|?Ln(d (|!:qm+?IB:Tٵ8ۈr`GPI8FJ(6464KY)nb#Ip>ùͮM*f5N$C+`Fx᱅2Yf/YwR#9?a;7aW=@_vM;E'dW=WUvd'(@>]}WM^خ-6=ayk ⍗M]牯^L8AEM?Ya@$rH\ADsqL T_rkQ1tL|'| 7|Z .6y3a5~v@-nQ%nUtceƍ_.k13'ytO"b(; lo`&z<}q!_1_%bхJ;,L%L$f@,>`Nء]>C7RP)׿M0sK8Z'\6, <:YtE? 2%ݼFl ]ScB҇ϨkH}ky% (EPYx@`y l8*\/co9*H܀(5) ÊRY|c[Mj~n&tGqe|фe#l](os&Nךn$z;LOlKB_sG *‰s[KZ} 3qhUz#ǥ"Xj(!x fTӘXuj\Dk=6دD؊*38"x,qiim[a\&p eg?t 0+Jp3@34hvDiҳv9u"rkťѳY&ko{Z<#_S[+9*k2rqD[F&1>vV.)u~][D9pek8K(=wH-9pE q Y>NaxEH,Yg֊3Zfd[)PĵBϼ(˯izݧW{9+Hq-h:GhC&YCK:eլ4+[<Ä$lf]EE`-ڽAͬF}t}-zVfPs iN!˛Zv֙VYfgVa/tY_mrY`uw K mXhK\h=2yJ憈"WYuxM5Z*urG"2gᇟdg?`JWOƦ#N p 7u2SLXnw!,FAs}C "Sl \nR<7?Z ~}L6'Gmp&3ѩ rK$ æ$sNR^/ \pZ:eF{}*3 t*j'GD3ōL:iGzka`"cN`Rb~W.ne21U{7L׺^7@s ׊.x~%.!w/f+=9),gP>Vg^#6d.Y@ PÁ/7*idA\ҧa TCNO&<\F趉^c8]V2kBt0rHqK/Vj(qz ]b,d]>c@Ɲ|Jcӟ1k7^߀[+ce>H1b2Za=ix|,=:e`Tĸd͹-Zɽ|OQ7[4uN޷rtτ۸VH8M*fnmJBn`;wLaIk)ʄCml7RΦoZ y:`ke%5HHp/5!KWxrË:дf8"1e6zx_פQS8=<=R1eUj\:HHYhdm3nX2}ϸgI'\L0Kҝ;7,x]$eFbLۙ- XsGF#ņz\Fn9CCIQ&R&RpA4b.MD1I,A9Givt ;41vnDNx N:`%^穄@l L 8v^'SQ.Ó zH N0⢣iMxwvwIN|c3뮹\9sEl;Q+US{8s,B؁ VNg9Fx FCPM /^4~ip + vpv2FBXZkFN`Z)1gLveԂ+dqTb-d_MZrSntH\aY@N9)>5qͼ. Thsr/; YlMP&&1!&ܰzC' %/wude[W8@Uf 5Mȁ?HnF>Ջ c#ac֝ 88 N?K-yeПP6?[ȡz:[9>OM"Z<_TkmgXcGAχN1Hs@FUG ͕ *s\<Ңv.!#l s=Ű`>dU=3wz1yz, 1c9 [UsWIvcAz4τ)Dbib^ۧ~rGJ~r5fhY楑:>hecUE" P.V"ljLjl%+2^J%6rɽytshpM=;@_^Wy;CEij3/GOK]NX%kf)N3_S.yG•.mÅ|ns4s7K6쌜r⫲EƕwӜPdxyWZZvќ|?qQP?2Cm\S:ŲmG_@KoqۛI'fCY 6s?Jz8#445qʦyq;Q d hv7J,Vu{͆C~Mt| 2ӓc O.Swխ#A]o{̵*F?-A॑?#W[E(&W !1`MylX*,yN=yI,8|Ga⼒/u9CYMM7w>^j,,FH=o37o)0z6dr+N!DZ5i3p0"\eMjC^2VW<'H/qƎоeAc PB/؂ؙե"i{o&@k9' #?fooX7;AgDT).Ŀ}`e@+D^37/dzٷe1&/v :0 V)J\DDQ۫,&*lG:ϯXiNcV Uw%8p:7Ҧ_~<%]6ezɲeyز#ȉ[P*8C>@pWys$y$Fҳ$nͪcD?&Ğ~NCnff̕oAR]<63w3G!pP&CzYB@I˲ |hpAmZLqCvȌ`)uˏUq,SvZ{lr J ϰUcw2UCWv|+nQEB?r 71_]ObOlq/h4~ʩb4 rGfɁScl;\2 P ;pʩZZm+r= "z®&–mOi3kP'Aj~>Ho#N6!h""# pM/\!E2{PhO|Vk$ս-XA2|q@Պ (\tE0q&X9/QL?>ٽ[9ns|is<;qBM 33+uR~!{ώhZi9C1CAJ U!M*ж^UF.O>NY޼E!<%pRwAlw*f+(b3 @5jw֞vƥ(q.{(kډrou8J5j+Ocq{n(}Ds#I0жq>Y?_.zl 7d4ЋD[ϝu)=vT<U,tOҺyx1_ ns9/Y\[ S]{S}s)˺lSs#mVdn1lzE+TYCh*80t)E%.<5#Q =w%Fl~̇\"^lَu.v;_(SUGN-d[=mB +W'*cQd4ɻq>S)n$:1z,W] &0ڵ} ֿVzO{ bS$rM%z@L LHh [ݖ:L P/΃gTY(]GdC_Vm@;.|_sUo++,[JcȳAS%7YQo"(}D{0 t41S?ܙ-RB5PSV22{+/q;\ :4QxG*gVyzv' 0C E2*tI4Gm٢R! EgA*0$vd H/L6ꎰ??V93].%9RiY~n9yؑ-5^a(Py0wqB.-K*+Y!vœEmBI+2T޸B8m. !T!x‰^pQ[u9SN]bʳ؞00K*'ecEF:ou\5q,Y(URP9Cʱ8 E Ғ8feӒ!jm>4Q^i80>5Grv 'aڂI8G)Tq&l:@z. L<4=2)?bPٞ( L<Ϲ;n?=YQUvIE{U4ϼPD!gO?42yh+B F4XIMFM|JQ0P-~#ѝ#=x ɫEd DL!rWM-y'Z< :KōeULP?z6X*}/"n˱D7J%@1R҆?sVNxq= e'/,ى.oDq@ǹG %Nte!Ym 94?L(5x6V"'gx)zYCUqVS_0pvhUw4Vq̨^,϶Ka9`!#D`.KF+>z&']D/{""qVB U$_J_͈ARo 6ꅀrF/4虓^LvʤEqCUTp5~mEpk~epsXc|~ECU6Xh{~l}?̅ț'zT)cF5`\,s@,0E1s /SÐk>1#W7<OOVTA%ȍls4.ҵ::CQ-&ta ~60.}~7v@rzH-O yF8|6Y;7~2wط?T\IȞӼ,]%U"-n7zhfݍڋiArE@#`߇>)xP3#dC2Q;/r̼#%}|޺ǃ1qI/o8Mq#)wWIY7kE\Nz@FlBoW sAoڥ`5tn%q בuŴҌS&D(f*⌒t) SX,AM7$`me ɗ3qHeD;Ao?di=R#2xA!F/O+kb-L]QUwiD#kSn7L']!$ဗ"Usʾ`9˂ՓP =Xka_Qp31x:²^*(ښ+L3ȣW 5͂rqj\cܶl߂v` 6-*3GT C a բ:G8 f+Sp݉؄ӎ=iO2€h 1FMɯ]]Yjk֭kݘtehE#?'m}"T#'xu]p\#r/"ia9Ҿ7_: #,!3ˈ%Edju?RMV.q7V"*f7MTe2 lЌ;Uq~[}"^MSC~muKiKA =,֞s*(!> # ʛ PC8MSXNĿ@Qq֢U 7,zXsWQ?(!H눭G -)RSMӾRF!u\28@щѬ+3Dj-_֫/a:!'Fk[~r}](?U3X{=OӅZe+*4\0&6.{ZO`Ȋ&Sq%ղ`.krjŭDd$pt\taS=mzմ')@dmcTUeVSbay"e˿4u"Ь<5] |lAvE@lK~6^#I;{YSJy炫۱>)?+Pa~)ŒbRM1y"p.A]QU@7|]}vǻAIm?uGU;POC[ d[Ň(z[bUh`k(.{Y\B: ۆ|lV#xPz/T~m:$h31LΫ`xf4Ō T5#˿ prKfuexg 6  Ƃ'["!2 -z74POrm'xtGY?1g4HuWs_nQc 7yy(Xuw辵~MtH)B:ZNMCq>L5^-@LZY܊Z`Ye\ğ0,hv'ܔ [W~:nXV*2q ,UI0 0Qnr ?tm{,/f/5YᴀGd K$ BadEOS>9IFqfP{Js*0q*5i&QT\+*,i@}Hj^Mv͝e))76y hp`G^̶|)̳q;!TC},7=vҿ<*N:u~G:ac'o*(F@d r3 gMhJ>f do~7 TX#wLsYu{҃lcI&VGuLSmMb`ǂt5{ L2 j!qg_~%q;ZxA 4\Iiy)H R),IX Jྦྷ$Oo@PkPr ou}VL}aTuj&>P;xD 8ZfB3(?Zw焜G畂̎x=RKNם`PACO)#ulQhc Si|B' CK&l܀qb;z ZMңA˾G~%X`R9v9o\xHc\hFY7 m8*@v J4BO kV3K*a.n KFi"hXj5UI)Cbm cA/JҀzq&~J*bƧbԻbAw@56V 8%9J 3QLյZU(q.bT H(J3Df(eq@>*F|kٚ2cm'.Gv0~ ۃ?z 9ýd~cr rL + ujf8oHQWb.Zv^{+FBh†fD%~9:T?ҏ%!a~q$CRJ3ɩYQ{]qObS$~pr.Rlޠ#uC^bb"tȲKY7yD_"b( B`}c1x>ӑ 1~1%_kjvwf(+ȫhAO~(DdHnZIJHiy}Ķ߁=˻aN&ym4ò&o[ `kО!8%3#$ʫ#%%ʚ0m'Qv'#1?q"{tO/.Q#s#o/qaL ()7矴eTv~aK|{M,z6k|*"<%K3תyl^i++gX@S/8M͔+ 3$1, !Xr&/s$EXN'yA 6ԁ$9\WY6SpGv>Ԗ/ 7sP< ejqjy#5;ipGSypQzl/; ְh1j0ьMrr "ư.]s'o"v/̫w( G1n1"Qz"|-}o0 k}"#nBdr@6#>|bHu5RD6>*è,7ݶdTj \Mer},y *ֺ@n>ϟO_؟KZU*Z9[";CYO 6_!r ŗ䀴'W=cwf9BZ}51<>;@ ҄K6c8/"OɪX!7"؟h~ 6ʃ9P ]@U,&\2%LA["tPI |u "deM3B #9 ρ/YB *׆P`=,xD;Ldn?Z#n{Z xn }=clG] ^z 0/ibI'[ AШ>,iqzq!QDxA^~rሰeT<HU\L2#DVo&p>1N50*vOH`A(isSfE-.מXz60G&ob|Ra%rE%GVqRd.<ұa#n"hAi JX蠉PhCIc ESZ1k\?nbsVy)lV{'KNjrXǗ[oĸ)bZ!wJ9făLt2PR#b< `zE}KNȏ8rE#HR4j˿U_+%NzN [!('sJB :,&ݏ[.l47Z1 T%7[ x䶲,|d@87JL^@X'죡PԄ t*Zϼ!]ZEh* :/A?}W[_򼭥GDS|yKw xEg\lUT 7C3X]ɿtx@Fd'C=a>r~eҶF]t҉s`fS |V袕:W=NCb!eg=bR)hI/ڸbod .=<·46kI@=;UPCssUń fg`ȲR!p;+Xo3RB$ޗʷYW$cLRSlިSˈx1YQO T (H z3!^V/ 1)CK,Eʇ$HaϬbn;0|&[»8i?",Mōt~A~=ĭFfߌqa[Q b=e6nHwPpBO=`@iAQ=o]in(e] 2-3|`K[6o &ح=<e^?٣O@qK{XAw0t qa9RHX ROOePē3!v=~xj6QW^!%[@Fťg=<8*{E">,e3UX~{XƓz'}j$ͻn0eF*7)0ZY3@3(ߤtJp:j2g Q.S$u*c:?q=gEZHRm-WcKAɘ'yD[؛0](du*IM0%).BW!)r?bР6~GDaOP`VIyGZpks1Ya \ٌ'I"=ERbp}{r"3hӚg*n*7hLy'0`YR3B<zӯD Lλ:dok^Y'Q@jTYa&1;Ahlc}@u::.Cb5}0p)vx~iTm.8`X%]j~ Czt]rΝUZ>/W~:OvwnY8& ]BfP& _uoIh蓭8 ^u5Q=+E|wV5|ze,,t1w併AX,t#uD8U ԣAXQt>;E<]{h7 v]z:9w"Rv%/ De*CҺ?d(b?InfT^ W9(O(_P[}…g f\.m6 ˌͻcG}BLHP~a:䰮/ ȲN [#j!_ J'>ˆtC[?܀"J V86G8[E(?]K[Ο8Op~ߗ l2Byt5NǺ#ne"_k(,r*C \.9ŘP&x~hedV>8eb 5Y'P> X.Y?m]:,WWldX{nPF#a8/ r:f)Э%HÁw{c*pOـX-3 :ghg&"0t7%[qY3 "vc9T㧦Ej}1l. @:,/1xϸz?c\{h}]!9kZ#iR{蚊/U3Lz8k""!>d8?\T*g@ ^;ŵ h&)H"<2H9e/6o熄 ~PJ.w"D39~;, nqOxƤ@5l|rq\{T9Ā#3L{쫶v, 9,f8 $!mrڴX ihoHAE[cdUE#/~㞖"O_JϺ>z^xpG71䧾 \LhUf ~B jC'Y 8@Kj}i=C@k<?P1rD.HR*tmL:nWL޳ v6gٸ]ë/m0S3" kJ8ay JE~%4/qJ׬U!;xcZLn$0 VCudgw0{H Cp2pK9)HD^Yc\*-lh񚂨p;? v."g;GkhzQɩ砵n1+fǦǂpÁy|H56aϚly*H='YRT'kF<hy,_"#.E3׷j}͓=2)LbǔbAe`kiw R,Ww;2XyL=.r޳:{&di!ZW!l/ #gnGVn/6`kʲS(veežE譭 |oSSge`kp C*'>8DB ixZ)-~߲<8/|:L9m e6XpwQPfjOYT `]+TٿμoPf>#-qPU+ea55&F1r~My ~;s~GB[׃I(wL#".*U9BV$t0Fi0I8Ky[)z(kO yCu044G9@0њbwve=Rkòݤ&n>ͦ1Yʨ71<nv I[_2YHX!Ѯc'r5ۀJE%E+; ZcڬTֽC:4='SGHRT?Z Xv4>U] v:Zo,+R~go4Ϫn6ߓPJΜ졩uJ)lI ڧ٫EBB# o͘Vd~5Ǵ/2[4KV%$ zP"Vn_hQqgkkvM6B={ lyO t~aXT.E>42ƕE[3hH]m{_%j Ғ/6:7+?TIQцsTؓE!& 6YbXnp{X 2oF8Tr2%0QHjXRC?*\4`Lu[_M\5T' @+Y&3}GumrU6 `\ ieh vG͜h-iXv$6 7*9{o]viV30iP%<٤(_5lw]P P;c.CMy)QSi+X܏Ղg\f+ڕ:!&jB4-cAӱxxH#N#^9VL*T ]LnV/3;G;67)1V(xk=cl1UQ$Jk~yr]iqS0);>,t. !jZҝkY'aOhA^BewF.XDvHozP :y,21+Mg %/`#7+KVC0òSlzM)BJ Ho%߀)tQz|@Ps&DG_qZ„ԭ9|14ꑮ=n]J yz@;/"aK{0g!o C7mjt!?d5hJ?R>yOOpV1}}_sNSGbAXC%6.Q s' d8F`+H1?f"5ąL45P$馴$q`V#|K֧nirL^ g{>2zER7"w@pfDYA7$O6&Wsicue'shnZOCzݴG}}ʾy4:b64OZWyP$ѿ@pQ1SC%?Gߍhb|?Y+nW8|Ef,s R &+pR{px0gGr8;2m7˦ }79_7vO`^Sw7e(%.50PR!ftPLtߙ/Qmj9MٽR*7p"࣯nQZY%H+;d*c.%"9KvJ!NUj rGxLevOȶvs]1\,KoR4ZKA%H{+/G çKM<|AS<Sh>K;ïT*Q*f(o//vփ5ZtO5x]Y͙ *Qˊhȶָ*aWi7 # fƅ:"1`S@oO%E4}e#.Oӄ)ʥvMHY;A㜳Wz"OuYhsz3~_*Ggje44 ?Ue')_ʣvvv*8@ !\zRh]聐M0: Yn֮s#CHE:+J fy@Y Qgd>ffDdG_eQX =d +rdv a` 3h!uLዠAKsM@Rv>FtRr$E5p^J.)R4FpS+рy@rw(.=%X-_L9M{8 aP!0t019\'A\ |VuHMD >CM0'V Kqv?̭Ľ8/)˶~S،1 $EcLr:ŰBJsٛZŮPjۤ;θk><ў.z2Þ` D3ų#K)3' e sJ>XRƽ<\TfQ,Ze8$0h#9xU=Pxy`[O,HTDE?CGim("[aN{e)F~W `[$IՋ/'sk 5jR2%:ׁ,r7C:MޱP3 Jȴpκd/aeMA]?t(;jfFyǩI.azT0xOOJ<8_ uFþFa+2ٕjHeɛ*dw]blB~ד0jbr[7zkjmD\[inz%^p##t9Yn !7ʓ#( ~uX_Qњ"{Z3D(n8t ]ܜ|c fZٮ]fw߲ Qo {7J0,+3YSmH]g ^HIJ|5rp0HPk%v+Q;I,K)R= jn, u'fxI$X4 V=UJK ԰e E iWTC Lt.;o_wH=!TN8EY<&Z -qK0Yz~;T20c&kuwƝ (br ef$HdO'Q'$V йcb&8ށa\&`*+AX ~-olgF?LHU\ǧ"4?M"uujaYln z9{_xXN$>_)K nK+J3*, *MeVj? Lr0C6rAb0Q0P_L+ $d(MlZq &9k[d‚Z'uv gyٞv@@/Zbci U'ۨ R_ysDjt~u s'Rz$ s{?g9d7l\4H&PX5M5{xi!mXŠ%TAb}O&/%yh~uI^]W ,nt14Ϳ(l"VwH,C. wxQ'zb_$" $cQ7Ih sc>fk.8iYb7s h(/X@᦮͏`j2ZS{p1!9K%?-AH..Fߖp$9A/G8t;2CG|pp|`}L%'5""aͿ3U$’RQzmq_RǴCUtGy@s5GsJ"$l<^چ>Dye3Vvs`F%I/.[~2uRɫWXA`رЏ\~l& ,iиhp›% \L~n#>ՆJFx>Cbd.ojW5Y-&JME *ba=F{U%Ⱥ[$h1-.gu\aCoTyv3Q!PI 'IMo ÝIÏk"*%QY^ FnK獨E{yMy6B؅ε{][xӴQbS{`pzב@"sɗhg)O ZJ6vzN7ƎFlIhuvT3>("%ZQVi=DRv:Sż)8BX^oEE}f8S'TMAҔZwdž|ěpΒ-}}l~7srŧ\:&ʨqx؅ENqǙԣA~DŽAoK*Yd cWn>Lص1~D8lG3@$x"n=_LJfՒS*z,}8#d7O/'JlTXRN+YyD5͒pS+~ŪjE‚Ԧ74@de5UE9UZӃKWdDz_yV>8_7El`yDD:@9\8,Ej⚥=a CA3z_NʊMWk޸PP-GU <|F2cUkC/޹4)ܖP,S\ȏ.C&נU7;xOF28I:Q (&)R||\{9C~@dCRVPUh'uJQ^\k7VW/ȓA*NĹ@؎+p^[HaÀY)]bA\ .OhD;+ml.6 [*Z*WbH,J/rX˱J~ GRw؂ÁI_0< fNZ!LYc-g&26>`Ɗ)r/D#=%VzAAH\{ROt.D_>ys!=#Bo[P e^ܱg ɥf]W.:٤`\V-;d.Y$ߒsnz=x5j5)!\7 2 𐗨Y-]p{4,P7+%K 0E$V2툨5qRŧp<Ԑ̞("; i:[H`@* Ӵ8[ TaI%{yH!~iƭH݇^:9rB_kV۲27# D* 4AC0tZ[8>0qgl$6G7$⿚i-[]_&ΙOǂ$_sH#1')@&7ޫ_.BܐbL2gbhcM0K ,8WNij]=l\۽n7sPÉ~VLXBk.9(q$/ř9Cr0L$.Cʳ3%Tbk|` THJ8'QG>Y愬cP0x)1}2bC0/c/K9[jj(T.s]Yc{5G IZfjȢ)-MY1 ʷf:15 DQ{ JHKThN2d:|uDXTvəp$Ҫh0f3U/40q 3b}[u~ڗq%8Fjs{9Ex*ј4UvwAS?HZSf:gD{E}0B NRHuHve>ŝ] >F{7I׍-N(X&bBYЫ !Bѓb8с8L aZe&Aw^" ;֦M|bMaMf_ FO/o:jOaW-=#r'3>LiڇD͜9DW^kei}qdT1|f5Um`o㭡bة% m):÷+_z?w g:0S( q[rxJn[~ZU+.:;@[,@XfT.e`bL3e`ؘޏ\q-L9 BNjsfKkC'%4N?)x?P$w/򥥃)_t%)hӢmZ|V׿ Ż,^Oqi'|]I<+I#ЉFJOyLpDq1N/lMnq&~lJFRd-_{XicShXd/ ,LRћ6ө37VZP*<~-Y@]38;Vf 2B#f(Aetū#T9@6ծ:=(Iڮs"kT ؆MWڛ1~̀LKʉl6{Uʗ'$ S.Оe41&rOPweejV@kQ[nSQbehxf!;AYҲHD  ݗf^_j멚v"ZEiӷd)u<]&TIr_@U{ugO!FGz@-x P)В sB<\J<)9 isz](f!30l>3Cl+ gꏦc]5'I/{gŃӌhgV^uC69eW%5ҡO&#*_V^FEY !$yC^ӄ#* OlH,К0Th $Agrzd*<fuCak9x5y t89bBt e" uj aAӫ # pp6Uрɼѳ_Q\,wkPkI1qfcFitMJ!ڃVARƴVcɋ3N Hy@V @T-|bsw91Py{3kNW=xZC1};'o[7=scNi+sbq`vvn?*a[pjӭM5ܥN j]s@fWh __md"3OW > 87Hr_ ^1R KY;*<@ϗeP7|\WUG/x8ꚡ$p;9-*(YrX -' &S<봁 9# ƈ<s$ѽt÷9Qmz8,OK"jS H/C?e*b/*,/)S DJ7t1-NDZ!4 ˶T*ɢS'MJ/}B uR1-.457X]hvo^9"Bv_Kjrܤgw.VF'S_ZK3xRh \*F +edgvV_ )[Z 謼Xo Ϲs[gV"881&J$a(Y+P$N0ۊ v֚|~m"*Cc;QDESL[GϖnNq XQ@֒ MMgd;3uЖ?Rw`<{WM[}^}xShCsZ8+@tv3سBM.c .ph޷&#ob5#~q4o 8) F=E7hD75?9Fb;4#-Kr83_4KCZk }07V,cws#ĨyGsHk +@3p4IkB@_?vf"ă$j?Ę)qnl쓿 X҄1jqrÈa}h~64&B {vG,O9=cm0!E%q(h^)^55](R4kAuoVF!Zv<?vA"+{VgҽXT[e~]7`PYIsm Q ER@$K0餽ua``.^%Ŕ_1xgq&LW_$!h0+W؞;!Ý{ EԢ 5cE|.IS7vkуp ^8Il}겏:/sPK ɾ_э9 Ygn8B9ysU%NŁU" "J(c嘇GR75fiOӭXBiQy+F:C&D֕@[̡yvʿWâqOՊR^K&^%`u-'[몒ne [T1,X HW>kz.J]hXYӤ)#f<__ ABM"(ؘb_ ` _'#I¥t| "3Ej2ftj&VZM?P3"~<%]m\ 33Lx~ʕVkB}Ūs VuwAԉw 4ߩƒI"U2pPFtufQ}OP .LB5'D`SHuZFTuA+4**gf7gkՐ>K<4'ʭN}sV%jyUf#sQuԝkhzoD =72Ժ퐒{=4[ :M =N2c΢,Oi.VDrxQzotr㎭^HS ` (.>,ܙZ=:+hAdavpq`陎5`oCTute h2JuK̲"Į2?/ 瘝D X lpbΪ2ܲFM8k&3LZj~ (K1<6؊ܜA &6luNM{Bۛ^!$z0{#7bUU]ъo$Зz#ChW|<TV⩓vkZLK݈afwP88-$hw^JmOIebE~Xeq6 /Z@UUL&i@POuJ؅Ep\e/s C+1կU{nE!ᚍչT&K!C vQulvCWuׄk_h<3>!U"* <]PJo٠R:,קcT+27 ;F5 _JԤ5.^Oh'H@n,T89ȡ h27J;B$0Ӭi螵MtPݑO)vMM ^LQ(oa mm]+yk.*a$)$s͌PEeQG,-u.& ű{qAk4Kk騡6}x K 5*儼Ai8wrW Y.މnvEFM#biv U7qƍ7$+ ojndF2Ym; [p1OFf(L>'`Vi:|z+ 9eb6V&DJrRi"Ta&O-s}m{P.n:mg1 O>-U vGvtt9H~is%yCOj6t Q8i07^ɧ+MLJsu(ƚ#5U3˨&)<}2$N{2&*{3z ;ųjt d9M{4Z7Vp7?MՋD̮W-RcrXK\ dܚ`z) ~LGKMVASӫ;1:~Qlj+3EvƸp5EFd7aw[],NM$̧4 nדKTv+M3U5ͰO-.+M*1LXeD` 0/`tVuUz}EtV=OMk X|r$.K٩d㮍@&6P0G 3 sx^g3_awRcXxeppBζӪzCx[`.E0v/ p(Xl_tWdRojh3Gܒ|!^t:zՒ# gMX{BY[*s %HKMoAϐr:gO-%r[6=}`}Y8DWt*oU0K%D3|7-ӀWpThКb*A! J:@7lAa1S7:T&<0:wX"+SW ]YExB %gqud3N##oӵQLq2)9boF.ƒwipy5]+F'Tt܀+8)Ē!-d{Bw Zqw6-K^0;껀nུl8yEQJw\b{;N]0f#}a5bX=dox*Disrs}bOx]}8}SW>ߔqps?`e hޗfd@k]m #SJLiaՏTB-¹သ1;]5+g!@}CO [P6qg33k~>$墫э1f'aQ|; HAĒԩ^kquL}\N/y^4y(Tjj!DjN} ?Q~s,7rRS8ׯ.J[4噀OZ= ϠLFOaڽBxe Qt$ c@HLѢL5:6DU\+!Al(Wώ\b0]<"&D(_;E6ZabOf+O\Ń%3!'l{iI滋 S&C[ RꍏKc,s9*)0SoΣOa\"|mҒl\2NHq }ڙgQg(ŒY^}jAW&6q_a9Elylč (zfz><~0Ŀzzpf8z|VV'p)[^TSp3׊A^"-Rc+ ([;Ose6*6"8?.n;cԬ2$y5uBr\Êq'ڥꇖMN8M-gq'S(6 饢B4FsH97GkH.쮢dv :]"D_ͨW|ҷ QQdQdV@]lyЀ>nz[gl?eVrL!hX+yN$Sl-pN0'q Ii<ϩ427p2ɍP eFޡ}Ck]h"] 3jQbmɮk{O>f8c ~y63. ~aCzo\ <|J;N)y'Z8.}J=붌ѶX'iaȊVH]ҝS4TuUWt?LM q2흚-|h#90ϵDW=]~n]mȦ B,pe,THt]" RXYPH6G X-' \>jClDtW:m[͡yɾuFހ",2|;.LMƞr ;U ["+z AM& N)#s܀^bٝ*8%p^-!߄|>N Q([~YPL񆑰ٳY᱁u-Iյؘc-pݠaY&WO$y-MډP*}]RAo,ѐYz-atqޙu/>D|Pb%$Vה&0~^V@\߷(L ]<$=izpY.{]gJH!NAK$`%ppc-[&;̍(,uġӨs^Ͷ PnzD{~^FMf+̢ n>E?Brg K7Rf'lwˆվn~،.2AZZ |7z%=,aǦQxl2^[ 5@ $-h =\L)[G>TQ+j玕2GK9;u/kc< Q8\͇{9//~t34!3gԬKYC'U9Lx+¾|#PX!驁vvAۻ|LF-u3>Zŀ|*] IG.doњ'/<:0*"z#oRM9,HF'Ȏ eipP{uji>ęuA@K:@/|(NX;~ro2Epy|T9 Nb eC 50Kb3.1[y8lRͭ{&]HS3jW RC"1/vU4eP^|+MR.DՔS; P~Q)Z؅MUJ|jH5HWBu'|_(;Á]aR #82x^j=̀+|+nx_@K_9 M@oMoDOiyٞ-cH>n)A:9F R.},{X0D⺨S_}'@٦@9UPF$ѭ{N+4|Elߥݲ88PmX}x'@!YCek`6i->A\wnCMݰ-.1ϑI,pz QTۤQ%췱xVi̡66%6n+>;HU({&*RY/K]څKPc¶%!頜\T!krwN*/< i'&18Ij##$e3SJ2UwmI.~ vEL}n;\/'~:"> ڳ'e&ss^- 㖢T՘F+yϝEr b0g+Sb' >kv܃u<>m'Utc ](1-}E9"\`,2 5$S娜MgoBHl]uPUsV6* Z4!I޻Ɖ" UY (Lg-8b|#(͉dQhzfZm@ln Xh@@F譨YM(FwU- a7K rh#;G T2Έ'4tnt!8‹rC7iAUZCpA9d1rSѮmq@ 0o2uZJmBҙs|f?ծ ^~ gQ6, ~SB&/'ӰMnOI%#ℯET"tCҚQޙ]7'/ŸsҮdwv@rܳ8W#`-w)u̙l=7@Y 4& HQ%O_hZB>7 >9~?#Fb>ꨣ,֌N3{ӦP5& JMMm1I6w*L(XX{v5ȸ8#?[聙^R<#gxt Nz|Q(X 68e!ҋg?3~tq?ffO4ƼY^ZTZk4˰n_KAQOvqm#"ٍϨẀMZEt5z=@݊  0Ռ_~HyhIR7M.رf{|qYpgԫj!,~N+ PgO&KLKJRm; LE3a"rX-i>N}Nv@o6v~:9G.'?iЕjCSeY"_|\&ffz="Ĺ-S-obT{‘w_v&]kحpy9Co߳$gh;<Q& $'p@JG6xXE :6_ |.;D-UMgW}!EDDڦ_ >ް# E 7v T$' HЭ oO h?R#%Z?EI`:^Ldvl9`z^'J׭QhLV`!!nmr_vlFWH[0<*4<䎠 fP3rCů]yY=QiMt.&SvzpvvB;U4 O:ngB}hN*fD|$: Bفeydh<iQcɼUr~9VB0D r6nCm!"~ F4F?H4BaO"7U;ov@2VT?lRg^;qJ\7jNL.tC>74^DOC]VA}؎U%Lq{5P%JJ4¹zt[>_Ncjqy qH%)E ځ1;[\JʦťXH1,$AkDŜ7#:̇TqynL7"; P@#A4QQ>(4ZZuN%ʾse7 ?Џk:{O4+M>h~ؾr?C"ѝQ:mӃuy{mm(b j:%:m('LV!maqf ߶#`u)ŅciQB uUiE 9߃򫕎nlNthcmꯑ]& T&b;D$Ս1FQK.7sZ'7 Bz!@ƙ?](Q$C$?6Td77( KK81^!Vn&mv؋.`u x"Z__jRg8f^Orʹ{u%? & Є CwL;s -8 扝$Lf,[8X1q.B?=1KxS'7@$>vR .dGl ^I͹Dïdd'÷Eb=iZ3KL8dW2 *tK_ gL|^SO`_$At1rӐ `=3M(anm8Cڑz|.2&Z2ͩXK}ܺPH+F}HIVhxDK$␲z>X[%X.ߺX !Ke5 R> &&26?F?L*uE)l|EK-އlzA߾cm7rK()؞1jdkI'q)X.r&`:E8bAA4D6;B[)bABPOThJKt$;A`oK[dWpG%58RiXqaM~N 6F #[~%xX: k5"Db_sŒrh Fi'k/s1>#UoQ.hJYG4֦eE#.PW>x̻zyn$l6%=pѣ< Lր8Q\T}ōӺpU!7R2ry,8 Fm` MERlNm[{-ڹ雘dDZ-w5/( vSbT->'A&„/!R"JWJb 8qw_xmԻ絃! Kt:[۹3^7,L|Gk?$,.+07$qSr=9?oQ:jHސ(f/ʆ 'c{k߳ߧjzkzoBl];A*! E-AxDuWJ$` ue'|Q˜RZ$Neы{g~ă]0ZOvT ?Ӈ>Eߣ[6K5{6. xB~9aj~ k S^,zxW] eJ xNYE.d-1!D+}3wؾh5 $~S/#r(޸w0?;pujYR"Azo@^ߛg_(:A2 l_2"%;% h˧k*7?Go9:/?ÔDHo]aNA\n7,ɹCBdGS0skeߒ04,ţ=HW_"meEJ >AҠ>bkRD廻T}Z_9WGй#> FN:IJfH=A= (6 XJ{'weBBfR.UB!v/ڭ#XT͡yͭ 60•8mȟh/ґ= A S}J j+_4} 3S= IwȆM{PmHG8| hGv<A.;ooViey^RKg>N'<ĊNŶ{t*-tas! ry]5pj5N$tqb}>L[9Ѫ2R@ӤMY:dJ ܕD=uǭ+7Eq{57Q CM 9@: v9Nh7rS5Q6*o"%bi n_.'kVpJaNkEoePٵ60k/0*go][/*`A $P:~B+ j'P2P7x~ ,e1p JL׻ ;)D*% nḋS:oڣ-et=Ǧsg‡bst*y)EAq'6 &SҚ-l|Lp$2g,ԓş@#%.WiId, KFw"7R؋5'NӇE`Jw,ˊ Ϻ݄u TZM ]qJ+ 0~hO^ 7 n?cc|Ij]AԀ=&f z!I|;B|s5|" lԜtWSZ.  06 xhǡ!+6pAvzhWnb\~(#uLj/bQѹ}0a""^zD]y\aSYf^ sI R扈zE!R-8Bwc\ yl?8LWwT_!,`mBBt"j/nwo'g߸x.#82.]$&oXf#6L]aJ_/ Ts`q$c[ŨAQ9WrSrcJC \ZmqjE> ;tY!hVr˸ԩغ,qM\zGKjCH%r櫟ӠΦfݿ~.W_C[1B80FnŹViPy: 5LJĩģqg1ͮyb_f/ R= ӕ;:FhO)EOW\u^ƀiW3z\Ln];Gg^Y !{\zu356Q>Υ~UK_Gu>t4dIlC&iݕ 6 GO[bFuWA\yzw YJLwh1Q: `AEbE@9 ITS>A{â7+><c&6񽣋ׂPT. WgT]$k0HL|Bk+ pQ6f5zAZ5:lvtZN}F5]q'p3R1>KGP~Eytp}hηv, B}yrlJX>Ϡ':Ẅ́?{udG{Kga>pr17_cZrf#\S&8K5C$>(i:-Ԥm7#ANֿhB`eЧ`r)(L#ttWY!8GBWd) I< yqUjJ,nUH&[n>WI9:ѓ@^s|f}eJ^1*0u} |zjb!5\G55d\0[a/6EizQ;6mhQKN.ȟ*E?cFwdOLRu)p7i074dv45Apr=P_\Y:Ν:'^Qzrk̐H-͝Njbi5bb/땠@u2S3Iٮ;' 4ZByj)mV,KWrqa+PχFs#eX{eR:(,[(8eeJ0k ¶))H"zj`#3I^h[(G(Uy-]Ihķɔ?Q!c*dJMycǿ u>%GMM?O@Vv{x$P0i+ǥrby}9્]z,`8VȬ'`QU/K8Nk IX>*bat|ccL7#l" z+tKZ9$_Sy6PiwNSwoY.:bYFp!଀(M˫KB1A]\M Mq=Qo~Na$/1GAC4}7LX6D `׻5FGVP;0vd-0ΒO=J=`>TPpmHiӽ][/զK3Z&m-4B=E5'NŚlj+Kӏ,O{i'-c[tn`LVbTVӏ1:t|6%@n2G] 2[vvgZb-sfKST)%C>R-=Z|K)GsQN)YjR `ߦ)\lܕ``~"y+ް.}}L>Et{A*ȼ7M,/J5Pd񌸘A $  +! JG4KwsGϹ2 L伮?&,ٛIKORկzq߂)&m8l~ YfƢjtɤO cpPvnO8XYB={x`K~LC>u>@&9`n=84#s䔊^^.MK ̖ai8# XXr!  [4f.7"*ŋXs `^,B}\BTjƼM%@e CS,Py+>HYQ7>pk`sfns2N#fLoo06k]尛@2Ewr!Q| ڮgl Bt@Br]ޑD"ˡ2`Kz `ce͕܈3EvI,\mnsH@i̷GaX)2pZyw)Br[(cg*NX)jilx25$h ?bR)sT䗴CQPt RٸkN2skPu"Кzo9BGg1XZ5ƸiܭRJɵ0M7=482 G^[A_J 7]kؙ\*7)JWg}&>8%e$1T]<5.O_mz;lM A&gPn0%o;,ABVʄE:?LLM3#c"P%i'po5&;75z%}a gW}jQRJ Cqo8< PF/oHE9фWC|r.Қh<@ev7!Ȧ~ ؀+Hs9 5FFWN%h; l&0VMET ^VOtDcP|OSuA"j?ѵs*@c拻>+%ѕ껎"Zk[PXY"ɩL:T2GNԐnw;kC  ľh &^|8/NNX#j.NF_F61kvڎbغ8S2 ϵhw2'pC?9~1njBtm6_{?h+nxG6?)#;%_Dp::Gf%X3@#D}Ճ+WTE6b,j3L͓16Ta001&URRzݕHה*&gnAJs>{\,v$q4N,i# θM-3㷊fӡj DfdzĊM[>\B*~ïX!OW``,5n÷EBb}Z'}d7q1U o{,a G3^!햳K;YkF&\ 'Xz7 B~k9>Z6C9$gzo/'/CɤitDk$Kq`}44Nr&▂Y5yL >JBEf.jp?LDXH63x- H¬ cqF{ rDRw'@63%$`4㏆8-.dS}ǯ_AM%^ !&Nx60c(kg[j[ID X:oN"4Q:~EҤJyd:Qޑg#s/U'C=[ƒ4 \`ߝ= 8Z3Pe,)ʎǵ]jCK$cѤzhr!?Q8TOG*b#BgUFAB<vS& sKF2t54mɎǰM೥ *=0C`?(Á{.NIպWL 9zMFPЄtJzMz̕W:@1ďP<:"—]ZNݽuIyuH S%q#DT_F~L dUGFm/MF3?h񲻼yojWT$prG)YQn<ӞS$^lTn$Y-.DBưqAfo(/'UJ< )wJvx}"mȍȥ}oTτylӫ}Ķ vZH (=1ҐakJN|#ep\N+LOC~OΙ,Uޔ&*~8k8VjB9jb*O}~e)o['ݧe4MՑvGM?a7-;]ѿ52ЮgT$\B P ps_]50oVw(@6Dp `COJ/¶5Q`335y*X` bBNcsV`]$Ǚ-)G ɥOֈTږraQONQ#a$X@k#B}|^K͕"Y?';=l@Pa bD`KAȏ,u&X@={w!݂IHi}@ /2LɥM%g6ҖZI+PrieE롮OS|tP I9S1D'++u79 3`ocGMx{!ΞZʆh3;Bmd- (T8۠2]YJbK) ll*X1Q3 $3辀M6; UB5 :y-e5qmΦ&WQ:  t KXdOlm=O;^dP~@ImaeErIܾAI  cl9qih Shy<m4cMfy9 m9ɾQ!2 J.8KM=AJ&vGig  5ꏃ(mcNŀ%qtWGx{#EQdԜ@ߝ'>W侖^UCUv oe?_jBp,W\IhXY©ō57 Bj]zĝ)gL}U(QCCsŰmZٍa5T\7-M- GWUğB@x*VpL E A f<{bgUQ+SG_*=rBQ՛+ |Zr=Q\]> FߟLӋk;#rwƝ\2 Z~Dl΃MHWx81B./68d~2;9QфK2Zi]7|'>-F)KYTz*%0?c԰&gu4(Y%8KY24w؝chs#(ʪVU=JǢ}6^$JG0*z p]e9VBr)JwbAl'kJSΜO.0z:TDIsAKPo@ՐIpSS&Xެ w\ZQEFكaYibYF$s7&y uy#_ڲҳ*DԴR3)/Śg;=1<,Ȭ\䮲^}X{ŦJ"~? $,.hlԀ{n8f!O/Z#$m}x 5ٕ홗pKիܕ' ޺1l1+g= 7=.}DkιMUl G5E)0xqeV5`$NvnzT]k VzsLtPתDd::w=W/Nq! $yP'2;AϿVf {҃p!3FGΔ4sTM$w1t%xMx9^N9T1O $ƫTRj1x.х+hkrv_`لtT+";kt4}Tk7r@Q\=K#F.퐡熰a ,` M"UQ41) IC#|D7s IUȉx*bp0Ԝ7IpG{,;DC|-}p8!-ƀFa%u qEL:IZ0}ebYWKŕV^u7}f\ffEWp)v5r*DDg^jIae>dfdRC£qւ"mF:Ao2ݾ&>I q/[ MD؋{fHbJ+Qk}OXduSR)՞Y||E5s||TN#iiw+m&gea?(=hְm jP# ?as$o3f" !'0WKL؅ס[7@-T1zctj;gXH`bl[#ZYpXRf[P߽ns7|7kZ37x92-o}D F GN.JU!Aϔ-O%a#6M^j'#P9]0Vta:nځiX}"Oe=87.τb.n-R}AVkqhQ75!BB( {>%ɠgkϺ48=k4 d>%}E}oXUZB׭YtL:KqUb5n) IK6m9앵]MUEE|KOJj EoO#Ph^ϭTpzIKx_@wm 9egfdd3+imcu["29to~U6}K)P{h!+Z6E?,g#Lǹ8izmLouoם/񟱧N (=5* r6r2wc/p|xk_liB4j W}uVP{@R`f%uR^툳H{jc`k Bg7ޚBYaYfzx!,@@Ҋ&4j^I0х}SZ$XD*^5bKUaJTk/;QH]_pY?VvŤJemEb.RUNO8cmk$AjuGC C/purxMzµ_g=uV1wT"^A@LO*{T/y?S&xR>aj?FD}.ع$+gÿQz9U'lB Uռ8s-)-i:t1x`' FdHUm yh۪ep [J<. @ ťoA(W.8_C/_a5؀A2$LZ!2v(Lh]R_bjg~kdwӍ~Ŷ@16d`5x4fɱEFK[6hv-E=F7%gRw1}uRXxY"8t4w;p?#zR"|o޶g!c^->BJipv3+=#iɡ(K^d:B2>p⽤Jwm߄9wVU{T><ZKڐGrH"(#!a?N+jZ[t><@$TddD8CCI'4Fj}kܱuGki)5|3[OZ2qgNlx7Kׁ5n(٢')|$fdD-%Mu Z:uR'cI̺T?}/c'e54%N35Ta;Q Z4JjbUǹ qw==C͢$+ qAiRbZ6]{[ɪg8r)'*;>~&2'e,Rbb׹ Num#IBǭZe$k%H@*>m _UD^}#[H'*U-KY}2Y3\`غoBД'@0xqZe yAl0lks䑖l`Ek\&A!,*lZox$++hf#`pNbj6.iܗ{](EwgQ_2ʤE^G "$^,bKmOM ߞd[O^) gl~f 4 e!^汉Y8J[..: 0 eIGn%?ؤ1 D.xK>H9㴶{tZ;,U+e1( Vm^VAe 7G8vU*o"b;2lGޤ3˳\g$p@_BhݫET<1To&ƚ , PM #O_/bvso,S m.:!,߱ʂʯ~&dYkpm,s "*z[bzOW$Sm.bm,{Nȋ~,6XDB#D(-)D6,e{` f|'M6t :O5.$icD~.Z!Z#aG£>A5őDW*j遐x:֭fqFOCn8ӮSS[Q³,fipl^fB67m _,^Roar0?OZ7C)}!}b?XW=L^cT U.S8ؒAPG?SAf6= 0xp;BΓfKxi~*QE,J>͂WaSh90VaYIpbh,MZ} 8fi0e oxg JF]Ld9s6qqfA$ͧr+i 񺁊 l]u)V|[y},m]_syЅg?T o;)㺋*.જR}RÇQ؉!^h #6v8 U2,n`,)&s+ /"خ5Hۯ^YU/Z|p"m=7LO{ W8Z_$c#leA6Pd-CMzQuzqyo1cݵ],%U~g[ 9? ]mqmZEeGTI`Uبik>p()ҽgLGʼnK̖)kV F}3wi8k~" x9jjlvǺt2qќ?TZs/Nww @{ Z`DS)p2uM4DX6u~FZWV>J?;ũ@FVk΂&]!}YԮ4uV(;r1/ YtyE@6Ti}'0VRqgqusGTŗTr*xIkB5HV\( 1,1*27x{a9ouR0ɢ ޡusa}'+9jŏ<'kq atk%QC!~lL ~4% ElXr˓0!=7fkmdX>]ͦwQO@N6~%yRr*a<3y,IOE;4A35Y@@nv\%uFZꜫu&l2\An"'25 F/KiY~=l*R}y>| 7sCO^hX&*8p.Z3Ph&Ps,Լ}?JV1n4LkŮȷXTHYJ߮:pKl<,H܅ zveaB[ _Kf&,_p,wpp}} XTLxΜGAC>G͛,v]ۿph8koC %͐.y WC4藪$n4_jN[Rw.c@Z39A7,#בe{u}=}ڗ K-IM -'Yn4ίd!ե{lÃk(3Z'BQ/ܭ<)[FrOV ]%D˽Bбیd.ĝ?8ފY>e|@;atbwCK&|od٘JevNVGrT)H=0!9k9zE [qlbe; 6T=4tCS*H2D{ts'%(VMIϭRTI+oNdmyŘ{[s]fњKP"Ҵ/)飔xpo @]tX++rfC RN z )0j y5Gs+Ō>s{ۡc4;ޅ&)xACJZo^jo.`˂S(78{_[!I,ѽ0{xFi_UMb^J\/:e C W;;@YJ.OWaw0oUL֩h~ Q˞<:,(j$sљ-4tK|CD+i*R% _Ԑ?Z*̺Xm&DmKEbOIgbw!1^ৗÓWFX!렟)QIQxxޗ v37n|P >J`;¾N02g`5]A1|gj>r7WedP *JŽ6FHCVT:Go0{4?miⰭOѩng_ i>vAj(/&ȣ2ضT3恕XF}yjy.颞2ؗA?!i ȷN w(m"-9; շ4$ ,)<~Jz[ Q/' Z&&v$xmdpm^q?ɞ̭XM&M W/h,k[I7U/ћ ݥ Ӎ!d+Sn9B /cSuׄsHbg@->LC )5+A2. %TL%AДz̡;r 8UN11 OtXz[!cS[gѡ:U]*{Иؓ-;=`Kh{jUY"̶2^(r>gv!,Pƨ$Q`֙d UDBbr$Mu:N[4S?=aE? 9ѿГ^鑣VmhӁ<@]"%g+*4L{TDfLU~a;;72P ȸ-U -&Ech4k M8ki'sТIə(Z+P'-؍׭d!opz;iDK'e.?,̳"ʷ.D7-el:{ C"" \l.)F*L5o gR%T%uL89N#)a%֢9r:AJnFC4L#[:ꛩtҋ+W f.gp[й< i~O3Y崡qj;aFo:A3*N5E-71VI9mŌ_Jaҿr "R>[_kWɞāH^_I40|ɲZMyDΡ-M5nTEȲd-~'`nWh&@-{Y:߷ϢE 5VZ0a@rVzV$JٲȯC@=Yֆ(Wu's aP\@O)mnd`W<遝5ŷuݪTetn MĶbdu;S 8n+l 2qPk`]*S%Kh"U/`50TrQyI{AY21cXy6y&$P? AL_k/!lv1דּ#b168S:1 }Ŝ`J↕pFh/ m-śN:-0HNB!wV 3b&L G _])‚+kLcIfS助2͜-T sOTKrem [Qg7&ȑsYP#[]!G?jJq}t+buၹB;|}b[ kkGxkh~. O yER. 8߮1w:Ng>#ߨ'ڬ*telsR2A$ 62J2LjP\O>|1 _H  ^feWҋ}S2'I$@Z Tbn,1'vbDXsUAaFȎ2.!P2mh?  r!J|xNꌰpɯJrxrqwell,U7zek膻{i~ւU=mH~q-Le؃/1UdVo(z;Tv 9ʡˡ KC[2λ֑ % o!$z#3ufsyyt46Y>̛ ӮH 1(1[Uhqvn%2dX Ѧہf;kԞRd7 /mǡ"?R[|&nn]{PV#6SAx#j"TO(7g)h>7znyT M_R؝RZaNr(,<n=ҡ&*ܨK_mg_g.i.6QAbxN$R%BM.jcM5 蚅 &D.E=uHBEoO+4Ɖ$%RGCj.<@gǡ&vKD2͂i 恎`Z&A2-W-S Ý޸gq#$ʶ\0eSZHͼg2Bcd}@GN} ̟'FAO%R8XT"dP.gٞȩ0Y{^U$ w9߀PwKg݈SM^pCU4D¦'#Hss0>  #Ѵ<DSCj=," =nG.Z[$f] ♥ 2t2}yAЪs;Wh,_=@3A{-[jpZO TC["*-t*nEH:N$ 4dQ3qhcQr:$i2`@TеYa[JcqL9H_d'_|Vڔ_yZ0䜳RD|D ˁ)RYYAu|n˝Uy^gpIZk0P>*凩hOPz!ؿ,Je&:>ٍ8~η,0*c5@4؉pbO ߜTAvjIҋG˗`7!1/}69N17_xWm9(f#I|lk9Phf3.f/Hz)9Sk,eQh]]դќ-" ƚl=!A%]rC6Q)۪ZW`%U17 i/aC896A<+$pEc 9'coGl}ZpKYTy~xI`pu6|W4}v #bԞx0g5S;",yeѱ I 0<´^dw2pXU|pQQ3(tZ H&j|d` ?i90AU?.UFgE>mdx_(oFD`JZD[(PW FiM{Z|O|HaR<+䳭AMUp%l c2H`/;T+A;%|kj-IvZ,'4GPg/̛z1?RHT(p͞IJTPm:ŧ)yyVW)uW W#1(V3rԏ&_Œyċ!_Uj`K5\ʅ(wsO#v=opͺZϽ~$"R_Kb,'k huBߩUIJ#}d- >&.C0 -Yi毹d HaX~t8B܎{T1m+٩vbH&w4'ZL\{R}|j&ٶWG?ti ^CZ $c p3~R} !oy}_v_ݞy|Y6Q hRll \?۶0)NeTtmXCX/;%1tmp4J/bJ{߇s͌W_}Zʪ+a٨|WpХ?c6Fk"ɴ "%r<̕\)\W]ƢVؾ8aM2UT*"! k7Lj6+W8gReDӊ, gcT!^}Rߔ/06JQ#9TiTU@)!SUa}Ou-;.KȠ^R}-`ىTBCOq15O{S8Eo kZ=h cBO>cdni̕ Gq|͖4$4*)Yz7 ؒc}jNim l}]'ᠾ٫jx]u ThvOSIԫf~,f+>6X%+=>oܓ$ノ7-wHB +D*53Qsa'ET[mQ;M'Q#]+;>rMB~Fg.<[~ԐYgA3󊄺~em3# 3jᬷ!w>_T@HG G]MYk`7#-7R 7ੱ>^t7PDXu>0ఖMx  rC7cXxx (# Qՙv͇аL"Bo18}~6n6AwQDo97HVB0^e%g&΅p #ns(R ;]}x \mCľE Ly/=P;B+fzՀ }ΜIN%|<7r<LPkiu TW:kd0zjr5`\ߞs)ґv-'͘`#16; BE3:>ՕЫ E%g?`|:FK:~pa9Kum|L bHKgFބ@0г Pu0gԤ{|C'6\uOdloQRXjfj4˘: f!!(Q8bN"{!p}{x 2*?iWj3/vZ3(vS60Ćvdf: Yh@->7]U(w8l]*.xnday]'NKJodƒv> 'kjw#)Lʄh9˺0h_rOaIË8*8Cǚ?j>$s%7~ԠߤHSzҬK^8͔*c ^Ra%4Z[AFʙsqlb?AGS#9rBpH-O|14 N(5 _FBж_'+Q X mGR"Q]3O|v$.Ҏcc8F;rDGMMvo>nlz!H++mɥXa %n3X}y`k;']"{r- ??gcq4O?WM(0RIЖ!gh&Lmųw+p. lF#{(NS^i~˜chtUE9W+,]p1 tɘ#AĬey )ʝ[1q}d[jz`C؅SQ*\zGb{8L-2mIE1;%>5k v%T5s''O-ǹiiײ(%yaQ=d0f_#9:kŠx qJt&}j4^Lt~pa&]/ﻶ|qG%0 iLҵdjᖈpctDz(Ek/IKHMs 69Xp%HCq-lEhSV%M'F%yrOpsҨ#io"yŹ::4 ˇZ+6GyQeeb10M`5.gj+% | @;C6KD5F]iBhWNI '<l"3 {q PD<+e=*}nr M@&SsW IFu|t[1?bn:yT_8gA@"0^E_H["EӔ <3Vޣjx NWVUBd֌i{0WLƺĖaWqyY:Y u￟VQ/bKTj'c},;J(~~F~9ʀ\Oa!@OO}r?^ 6ؚ=Z]fPx/vQl/Gǽo Xl8K+ '3Z>[4{S72dGJLܾ-c2{*)ոdFfB ,uVFn[K4]1_"3:rv?E /{ A_fj>]L'GhK9ٯSI1SF[@*P2?͖Bb^N[(Zc|a=*:e;:εQe;4YΞ/?*Cu"A԰:O3<chu+w%S |鑮wHϣ7$J_kģC\l?Mڧ6H5x6 r+({v"j_G8.0BC^?a%qf6񶵆ɰD2L8]h)'toJ.8wpuofvE{;{;Qp4ŲvK׮IDv ;lϕ]ֽNpm9t87)n$+p( =97Or7p%ëp)g=[ll(]# nJ !M_0PLiT^aL,Sd<*LDS)$S-,A3ޭ6"X7L|DyI "&g1: 8'zpaT[i~H2NNKe||XiT,|DJTXsU @a]Pr }Nrhu4l$8p.  U܋nJqC0CGz5e%ktgpb g`?yC(xl곋L`:p Y2+y/ OTwv '_^-K䬸_ܩ?~䪬QlwrNԱ{h]7,#woB 9\*0v8EtR+yw[ԯh(dC&+7@]8WbZQ Gu=RUp:Bl=CK >&< t;YK]ΚO;Sܘ{ Mr3w셿p Pk>.KpL`K^;e5mٝ09xQ8-Zg&{(x}v*[fᐋFL:ALraՐIXY8c+b1P5q: T#\< lN$[@]BTTal=zk8 ơ7*>^׊4";E;qvw,,++Β #BGr~@4R_j2FҶp0!::՟zruvFWpJR3--R@.H-xf6WҷH8iL!@%=:] s3ljSQ\%愮WǙ^zhKTJΕT=y=`[W]l~ 2x@zxP+HzWQZ{ґ#Y_g))$4Tbkٞ%h@PYqvVFy <6e;:ĭ#RƁR X7_w:@rTt{iA&%*ey)=2R;U%\>1DH֍!5S~yUdQY}"o?p ;j;t~ vY\M8.;pVz`Ι~SߙlSN7MNl1϶GmBgRYN9@ zzk;t FEw"cgtx0Dd+zw`/?YGYݪ4p؄287W.EB{4hVElaV4ΨbVxvd͉aYLs'4vKV櫃s-;W8zp+v(HIs~a&ՄB5~*թ*}wX[J=1Fg}+L^ˬ;d0m\D9QY%]Durl*Nty6U4꽿]=a 4SH=?5%{{j(|"@t>,f% !^Q_)տ˺䗫U!NQ H%‘+)!!+%ys[+ozbQ?PVDohHǚŠrD{ ţ8DA+\ZCNj| {I%%Ҟ22B"n|cf(l0,_9Dw1mFzL<;ЀoI(-oPk}{xS!T7'c/w^fWU8F,Y6^Dc!ӻ>G ONLzSB,4I:_.K&ܸe>ʡ~:GρGG=` Fyhu b!80RSqᮗeo?+JR$f=k}*$0:VsC[]KBӉNFykO.4W(]Ł9Nć}:[AnFMx9WhCSNM' U\4O=zwSHP/,lpŤ3k$*[7dXa~5l7>`+=M7JVzΩZ w!>t{_ݴh Ol^B5Ys?œ9d _Β a"e kr.D0&)9=(#;pFcoe3 v$[6]lt#{L$a[HVx&IG P"" ɭ٧"i$`-ȫ'.\"zQn|R[aj&_ Tt޶VʡXj)ba*[ E0@N=K߷{_cgzhUkn->❝ @8+?ՅJbY1^S"歍##Oc,sT{$1"r lQaJ丏hW@_.TtגF@) yM#>[ŝ "H" k dz~<5{6EZʿ^T3A :%bֹC_` i։1DH>\UL61uD F",g9_@WT,:%xQ"BGpd>/Q(I!Q|==ItWJݗYYﻎ- 7CC)UjYry`GM,(]ٕyƎRUn.9^vkidvGl,3A5=tto+^'4C1`搢qf==QTA_?9c(1P zEtF\uŁjJAAX@J尖l y#@D_L%+Ӝ:-Fꠞ}r Qy:j7dX;lwRB& WCrudf{hI$qƊWbS0yx] ͔i7F>E4ΕG{T":Bx =IWܴ(x`@B 3=JPzFkCT ,r\mZiFBߒ`Sd;#5aT]pioJǓ'sݜ-h^gΣLZbDxd޵b*8#h>.BcwDΖ g^ P48ģݓTnkns:&&=Vxly{`,9yYx/4Y\5@bSmG7TiEC)g{u ԿF.01o;^C-gO,*e`p`$5EXL %fqh0,rUu"lNY˅;U`1b?C0Obύ=ʱM'l>DKEK4߮y|LSdN:r1zMb0`rUG-h&.%/ڭ3NqOx-YG4njNE "=txRiD]A=ԔdӚZnQ*$_ cZj+<~4+H.e^4\I}, ڏm$qGwȵ;?a:eӥ(ZEgoCAiy+S aK>S&ی2SI, _;Sv#^lyFAL* M]QrƄ)rϔtН8j'LL(b_E#Jfp4f{5>z~ds吙%.Rôa!^tZt?AHIv]ne BM.[Iq׺mPuo mS [q=ӷ܂ϊ+[J'`01D{S#x\ nc0\fx3KtX.kBc aK4aA2Jt{O5#Ph҂Y f4&sv*jb(5m촎낹AHp"tݝ; k3#RN7E'ۼ |H=e$Ғowf%}~F h=+Ҽu7DȒzws$xmK&N[},N QDSv/K 9d-:7_FqEF|rG]!>5LT0Vy T&gkp!SUg\2AA 3H(}y߶k_3 *[UJN4Ά'Sl=&' FX>&d.DĐpBQӤT.hw2"@s_-4t5Vrihdi RFzY{PL^䂻,fF_?"_31r#j:(Ei:k>0 C\ ZX)ʅ0zo GOV Q|I/(}?g"B4GH*JD4YL3KaD@FiK=jЬn@uL%RqUJccӁwbdbXZƮܹ\"k=o M^,FӔXr;Ѕʐ杶ǁ$ڬFµj2f[Tia%vQBB[R\b*C_Xcgx!iWO@ OϷ)59|j4ԎW%IY:ߌyvf BܻzJhr!_(+ݼ%D!bc6G Sv=F\[;xu}ܸ' &d"ҼL|Xnp{̀xE"U!HΞ:p CTyAfg*!2 JТo8Axd+K}LTDe/ %V^7_b¨(N^nLYC@,RZL?$fxL Is/ ˎ0r#*_*',r~qullmO_o+5flU ie<7MadzVi'd3NJYcra"#L ʔK\M2gtfVȔWߛޮm]dI@#S%t`mvOz8J̅dP߹ :|H#p:|/CJ]BL62srxv+@v˕*h r c^Wh5E;V`~p *g̿W4j6Z<9r vZeo'Fz4f}TCJ䋐'71GOjTY]Fq!w<[I#Cw˘$`LX.91 ‚SS)ە]ʘV1z´PhR浻(T/ɹo(,9DsI=wc$qzFR^z<(r{:4>RRULJ,,>{K{%GTmFdժT E᧬ڕCfox}G<10 8WkCk%%!e"%՛zNƢqzVE)+ Xb? %]KuvmK*u]Ж$Qc' M"1^PMbh2[ g!p XKV}XrxfGGI(b^uڶF69a~yV_WNn؆Y6 g &G?7.*wnI#H*t%]}]S'zVAI(Eҏ^ v: Ղe'jnQR__ 0*$ f0"pj>IosdWF6@W›$ggHf9 v*w$Fz+C %L1PJo thrgflߒGՀ:5tĜ'b6r nZs y7ܭK-ٮH'11^eQ]}9ҘVVVȥ8fG Z6픤jqJg"x{W.%)xm3.#jJgRCcD^ԀqlUUm6+ NKy:G!`j6&| M;,v;̞̽/VN(u@ XJ&G X3 t 3R셒ohrUމ0$3M{L))1zhitaf߸!1 'E=6zC;ȉ} i2ca+Wo/C2DkG42^7pk~(7NC/Ba _C3eD~lJeKew#j-bjOIo mWa~n5xXWz"!(_DЌ;|9kI)>/ uaodޠ)LRdT{(| ky{Zj]#$G/TXF b)Ka_i*^$8'6sbNAj'') ׻#8!_tZvgJE׵ SQ~c\?NP˴K)9 Q'!n/pqN1b,ndi< +oZ Ǡ%i g鸪:fF*W$&@QS/q,TuW_/^JiA!mv{/xZv­L90\*Gls߸mH4L^#_zǽkGt)lRj^Wp NPi>} F'M5-5+gqt QEWKTOlg(&E+3,F*.,#KzNA]8i.RI\D2]HQ|ҠUi }j{#>+oSa FA$Ӳi:ධy'#;,I#-;VÿjIR^@讱L@QrU.9xY終+Zedq[#`41NhC8렒()8wgwYofjU*mwO4٨`$uJpkR /˓&953+xSWBc1}T'bJ:nOwS2b/bsXA̋o\s9Zt+FflQ :Ƈo@#~X{N.^ H1!<sh 8eG#Ť_Dތ-/"liT8>%~BT>ʗ WH&$N_$b\jG]wtOʱa:X"Q>G#~jAIQV,nˈ&x6R|o)/1\Afq1,1P I(gK %K_ [~qmQcH}!(3=ـK95`Rt˺H}4,$L ڛ\.^,fiV{wDF.8ewH#"AN0;,\YX@9y_唯@ ]L;CPۓ4L>K8Z6 raeyԬr5bPs]ӋLg,{7|\mn 5B6ege͂!w*|IM"V 4ڪs72B-2d3-Wca&m -\<3}rYWU8e܁,<9N$e)R},=W=6fHC4,xbcܟZ}rP5x3z;49|H<,IUK=&acqmrZ)Rӥ!+$m, /Ӊ!"ړÞPd2QBsxvfG +sqbZ#(aL;uOiW%zTfUSB~QWyI"$UWxgWRO`ֶ e栅Ac$D[uc 5HDPObt5]zy) 3bDQETw|Wd:~NtP'Y N|QS:trh kJ La@"!8'̉p1$`1Fٽ]MJ[C'$e{]w$r o;D'_!uB$=z ҊX_4I7#A1;2'}=z0>β\9 JڒZM9$輪} Js+Rx%FfuF<~ZI%#o8c0fru.FJN>A$?! S̖'Ɨ_*KBho@| \/jSц"tL 1fﻭ@/ -B=E(wuر19 <@epz@-/'q8ԁ7NA"o`>ёO;H?^,LQ%H8,!8cS/[f;k;= !V#o/fg~ 6vo|rץ[I>kt=|Rlעc%'e= sƣ&bԷy~‡"N(!s@ WvQM͗lG1yvr"<4-KHWu":1/̷^%v3rΓIn¢l(%<5?j.k?RS6 bˊeIJu)Bg7_(ly'vO93|7ޱٷK9$>6?^ -RLOFk > Idᆚ 9 mS7T%'#h`(ˉ$$"@1jYܛIZk0w%{,+t22ݮf%ʀhPYl2f9'e~"]nu@U^^@gjF¡WOaA{ b Zl.~.%^.ISfԙ(0* /iya(;A{ .›H.4;}(k{|py@"aE ֭"W\nOG=rC2nO!i<H .vH  Ȓs J9l!lDZ,m2T8 Z+J޶Rx#ѶZ\"r2#KRfBShS!ٚ3G? g^m_6a6n&=8Tv7Ƀ{X2(P#0_q ˬhX5uw]Ug0Nȱ?;&UpE ya`ԇ$hP>hAK< mp1LSȎDk)oS9A?ޥNCK^Ƶ#]m  ͗eJP嗑T=0=q4z2($qENO:⟈)CơC6DY>Xވd"^;"J Fx {Oyz.!x@$We_^hmJ#&MWj*b)>iœq_/gB\`m/>M[bs]]8S (  ѹ0O8:3]獿^xo{awA\E쀞F$gdF0ё'|&4;T|P~ ],M(KG57` x-8%-D0x_Ǥۖʷbxʶ@W枵DKg$'Wʎ P 8 Гݫ`曘Asw`@fͻu@YwqIRe(>$X0D@`94vneݓΜsvx8#uoGu”\exj]+=` "g9;F07eR+#B'RpȄKDSh-4R8y&P3 Ý |ANXeW~BCOy+yƐ_4LJy9' Xqǡ!$c~R?{RFPxKD/9.#>O@>5@NkTQb7 80EaOβ ~ZyVF&խDgDD)$V|aBiLֽG\8 )whWޫ=8JGh]x3 :3Uz3޵1 dPTϫ") N~*8]`sr*w*0_1wZX"/"ejaaѳ}ɰ2*rJ!kHOP'VޖpTB{LhT=-<_/x(wnCy"UvW\V^FEX&́'" \#:Dvnl!U5[@eQClg`=`#c5]Io@o!jjZ@34mx6r_#[Gr̊hxbdeCDbZhhh[,O0VR˘;SH.\bض[ 4VfŷH8f"ٞ`66%^6~ R. YH*ӓIpW~33'eRBXHAO)ù{9`Z=00%X5S.R\)!"SaRO|9̡E0C;u&ɏj&XuD^=j'rAC?P)Z1RlʓO.QR!,r@1(NŬ$~DZV܋z_,mO+7Vq~z$ۋ`WYR:&{^T0Ͼ t˦+ylNwyW1`op/:n͐&GH]`' s+ڳlSH8)^/j4|GJu2Rce踜_8OK%9xI;T; oS=[goV3Ðobn<Wf]ȷrO{/{͌LV2``K:4ׄzFIr.\ 7*w[cy!#ZgiM0!i4LTXFQנvtwh%>UpC׃e2fcux]-EޮKRRkmu`X. r#3,vIWf(tr)@Ű}qrDp~hU7(x=c6hɘϏ\?TTҧ"mAyg+ Yp]iT؝$vsxZ~brlS;K}ia^mF'C[} "Ӟ%|[ХG|{g1)JŬtDGATCVtXbįFr󴸄46FeĪs Hr0|t5+jTTbfc.p\"t¤~ C⷇U6D:ҿ&V}StԐ/_Jҍ yKS*I ̧:<ʁ;w aL[0$ v6$N vw7}{-;V7xN̼A?Z/W EL;^iD}*/lΕHqzoQoWlvS&UdBWmt{RCT[;Iza{@ 8(svxSg }V:UYcXoVlEڨ"AD'cSKLGyDL?1HB!1'h!"z6Q7 TZNJ~Wb=YpҽS9n@VHT.i8:: o%I> 2Z |l1L!ORq*C,qZCH&y kwb Hپn`Ϙ oz| zK2.eNɎ+S7oJ^2BdsW3֠838 EE9EFr a8I:0圾Cpw /w)Im@EEjzo04A?Mp`;3A|\,UY}/Ę^pjEsl ĕVflyZV~|I(14pVGsdxwqZ.Z.Fr.kZ,&dwGaI;JcÓsPzϤR'.4B@$9k"۟O杹(]o c'ni?#i4߲L{8/\9NqK@Յ<, vl۽gI{S]T.9BZeUJn9ʒoT B-3`0X.`c|y3ٝ'fR->:$nWqf K'eƍ1{ی\^߄A"r ЪַP1$&&xE ãS3BOF6ApЍLȣ]zR^IW%V倢 oNk-ܭ:MnGKv|2zM o;,+I֍ "pke5 ,bJQZT 8?C}~1'],2FMܤ` n"O _tSg y#ܛn}j wtq)oe}4ӷ9UoݎnF_R_4.ќ*3:y-XȡnWz<܄R7=y4_u.n/k&QE&/;CJ*#gq2; ̙G^->o|,X@ JbRQ[<K5Ni4D t?!d,[EɓlmF/skNZ8I:0BQ9BbшD6b V:΀F@::9E~Bjʼv RN5Y(Vq)[au號bH$="љiyf˒:M dLjF|fU1U9{ڑdHy;Dj > pd\ 8R>8K^y<(ߍ݁ϨM OP#}Yϥt,:XN:^cOfUK|Jo\T>/ݗR¹0ǞJ}A\E7>_]WFrQM)v@f"/[yF6DY?}2Zü֣C3Sm,>N Bp?b|C@ca36*(;ipnT:b ˆ 䖜&3ibϲFZuk3ShW u2@X -N6KHRt~q,npLQ-)Ζ,jʼ97z}:Ri/u*;gPƐ2lZJ^+@3lԢh 3qe¼,Bi;&^5m3IK~hfB87mdb jHħKY-+sVn"?7.IIGԒF_X`{սKt>7VI ?/*T$ᴑo|ZE`U5ILt#LI Q`UG'0o-=+^nzg-a4 *+K߅0 X#.܆{?eTW̤P2_Es6U d|BIU|[w̵ =]н89ֳ6]_=Ƃ]8[ByZzt+?ݷ+T|3U*BMѕ~%>U*כ2D`7_gFgŲZ|1 C{en{4ʸxBS mnR*L pDXXlbʘ@(.V)&6oPu & Ӄz⺇>3UKiYPxe*3VWH\%O,ƜqF)?F@\6rFjHV( xVEdvm$PE֎ƫʢa75C6^F,Hn+a9aXmb:JW;7ܨT)rc%H*UU}P Ngꪜ(<w' S7krXTQy 6ʑ$;,"l> sD)4sh)92ND6gosN<17NQ6Ç3ߞeJ?? -@;c1}aR3ȑ@@U^,Vg@Ԍ:X;nZ$2-tA.D8htlMQ+Ρm/t7z0< 6A(+-.nwYY62y$ [ Fbڄ't#djUPOu⧸ h|q>y5v!&@ MMa 5Bš]nOCȽ Y7m_hU;eYn)E_wɭϡ' ,1q2wT$aF+z67t k -#fUYq.i'~s(5} fI0Z?ިןXgQCv7Hd4&J)-u $P9UrR9!bjZ'/gy׳ "q BDX-Gvf1 f/P{aA*  u]XexXȋ{ja3 b ],|BކE{,2A4≿HS?Ef n#sga=A$.u lKڜ`5{\`0_xzPV!QIU5 kaLmi=mȋ)MYċ5,Ă+_׮6#-*˖P(Yk볅Һ#Zum^>h^kԒoN*ZN&-a{ݺ c4iH>OLo E" EVtNU(M; @j*Iglݓ`4eogjCniHiUVy >Gj΅ɺOrB)dS/B-"w u2i84Y4`$H҈w}qq-SDY $1^geR5. /:}/(%ZC`Z  |FQ(t5F-n MQ/ES1|FhI8rAom< @G*Wty&YE ECeE]_`CeiO%ǟoK~%Z0cAF#,ͩ("ʨ`3Dx5=/dW$\c;ʸ^!@17=oO;L1YX]̦TjI^ƪcyFZ QEO3k^Y >lmATԛE<"2_z[ &]Y`0);_$ZzY-8RU@Oa2 T~9ZGt\:6R6A@-l.:}Q uOh +|39lgV;u/ᬅ%pQ{h]`] jX8 "UuC0c#4晡rmhf~HBT5QYKX.ìJ TL{V8"T5)R~ߌnu.*JYʸ-Q> (6L3W~i64Ph1qeLј9AUPSl=E)8\UVZ!7XX bD}q̫_؛-(}C:op8F㢅="T3h%}RJPc+&GW+)=B:)yXi@2Fh,xe[\2VT/bn^Y\*OEyw<66T~dו`o?Eb/F)J܍H@[5|Va2BDGB1ƙRK 1Κ񀘜,^:‡C F`oE<A~D;CE2w81F|A/Br Mj؉| NG 18PQ/X\ y*QiX.bl%ƥb}#г_]ݢnnj9W2ss3\S51> w*̷& v0Y.saf{8c~[B6_|Ua>L*0RQt%Q=g1mI˗:pҀ*!m}/H08þM|lΆnl5RzDZF; : R H7JR[pDiERm5FUv<2WrXج u~==H01gYVAܞU*Ob9+s[[KtRY&[uugxŕkO܁i)&m; g3 :WχQ?˃9nbmz (;tdmVr`T]֑1#DEnjj֒3(Rȋt_\ߢy)rSr58t|z!rsQnfRlgAĐҵMl#mE+10] ,1˺B6cׅz(1kg6^SI"omm6'|-32Rc xW:"2MET4X8-Fs 5lL*,m<$)1R #KEvl.GW*e3UW [,Ō ŦF#Ôh7+:]%~ puM\)y:Hʬ5mqu%9zp\e y]=p/\zoDU^/XBmH+h>M'&d)XF# 5C)4kZ8x^2(zv":j d$|u؆-Y]ĄVviۄ[,[&,hNۇ67DW9S!b嚂dr6 mq=਎hBV*2jYv|iHl8qA b<OCZS~uRxQ.:4Dqlv? ->k~<=c#lxHɏ+S]h[h0w&/aɥq@T*-JǬ! 2.rcN+:p}g!̨pEΌc z92ީ $֠nSO Gml7>)7g&zT!A 5spҘ3ҭ 8X=0Wh Y'8N'6 PX{s j8yמa#/黌LTBj'YVh>S~ ;,-&a<<7Bǜ0`]W^lU1 m^}=+XZTUÂjBAhvM7œEAV'}lq^ ^MK-|kHN» @\txM0*k\3yOugI#bE |F"D;,H*^܍UҠlfR4ə+ ]79X{gnv^VF\sI2u"ٟk8^h`>O䃌3< JUq>*Sx +0oPuKkiS;WRe0 @`A/o{ ہ\Bщп笓8%xZyȊt Xv0$y [b6$F?Daڮnu,is#,mreTo\ZЭO7 gȩ&5>KpR>% $RNҤEhH%lSXɿ|aϥHD`}=>P#3bpk;PjF{7CW0Q[y'^+?# ]}*dRQs4iNtMMklx6U'%F9C}Zy[xϽgHaiGoCs$ CJ4.!EԽ:AR90D̦t$vOu|Og=OVxLkl^lJ~ lex&A| ]WO ` ̾Ɉ&vdӮɌt${F._$+ŏɋts@5W D{{PCDilODjfه1ڠЬtT%00F2̏gm*մ!\hl+t96`RV &8[Dϩ,۽KP'Yq})ڿ'h2 j|PJ_/4g-+f;2CoeLN 2J 'piжnө qȴxE痱* 1XŠkWzcn`HO@v!!;Ӯ!ww; `*$|D w4SUhBB"=x5>*kCCKN'dRnר>mobtn?w65 "Zĩ{fi Ѥ?'K}'^*V!uR"~jH(ZTj؆ $[`b:hG1a2 rТZoT dո}Fr:L elPNɑm;wWG0Q@ZB"%j]Z^<^8kp\ҘG&Tn[8Q<m>]QHn&Je)-UQ\֞n*}?V0msOfĜE$dzWXI 6]nlEǢG%(G^U5w]GЯv uk3}'~qF͢/N $O@/]a:4n*_̪%tI7{<'4y^&Kvg?`)̩9YO1 "IĚ#7;D2W@oc=3>< PMNSn!{A~*@mуR*/*^c0їp'|}ecw@[%˲н0H_]L9M9uy8IzW {g;Ut n"a!f7ʄ X Gq؅y$'WdZ<~AL;7K)噟ăzۧt'_ Н\hxH6s5!1$`Ћ{4uIQ93V1dsΈ_I4-HpqeZ2/u`vm gpCGXbT;ڟ)>&tnjfOy煤\C|}hZ sYܿPhv|/H_{=qgw.pBOvwsn\7JJKW^jz B7tβZLg: LYATvpnQc.VoW`~Eyj,GqϣvbGo8A3סTB7S@"XF.#weh[MY/5yŬDq/uJ,6;](cm2| )&-2FKqұYzMQOBBSqֵ<9&m yƒE:iIj#sUd&RVțT: ~au18$ ez\+z~V9$1`W2xڭاcӱt(Ͷ:9G4EזJN5yUt:p J2mɻe3b(>f'a+>eǤoUry(OZX2.R؁^vC-w[Bӿ“XWY!sA _s6KMN#ShA( -PQ'* (րݰ>TAZIæ<*mCnK:Q{^W| RkU,!Rm+W0u oDpӭ/h 'ܢΚ BDʕqxmEԴ=Q<"=TB^nD]669TrTf #u T໪,Ǔvrs>e5r:R[$L+ӮC˯=.58Cm'ZT~3l+ZVf eh"i]~aH"7N0A®XbKlʼnK HDGїvn$Zҟ9iiByYyK]9czL*4 1ˆ5'jE8 bս>c!fGZZi?/Mk4U﫶̔C9bRX2U7TC@`Z⣎eVsVvivs%{ *TiorÐ|vFVCxJa-%dEʶx2`LLao+YX]j%y"D4 ;"(+.]v-33 Hŗ+Vlu]M\;iZ%[Y7 //7>%7qcOyza2-br6w57vIS?^xj.W˕?9(pcX26Pأx:`}M@}ܾ WJZ׷?!H ?ԃQc&2['=^9i.\^\^Rkg%s(/Urr)UM;Mj,]|P<.C4@*0A0:Ko'L+d K+…z[1Г {FQ<tyRݫ_mK!ÌiB<%\̡ ]"HM7Jˉicl)ko|+?TAYrތ#q ~|N܋[3 ]:N;_Rznyj ubˁ=\<J O,bxBb:\Lip-]oԜdLY A(aFqg >ڼ n.ZCYJ%IXzV.!V]"hk ؠ^bwo6 j=]r~P(Me脺'W.a6q_x|*H{nu-waֻ~~J9RݠoY t``%4ANp,8t@ *v(=yvF)&^fVV*c92(?wʌ/r.(w7w*{o ^"sGea:}Vcr?禼!$%[7<A#r'CS2T)lbyЙa܈[ğw7ƿwVj#ٗ6”Ҵ7;aO*-`[۰3y)9YmŰ0p#B3\ sgi@Y㈪sNo7 >vUMr}N(dzwhIj87ЎP];ts |;p W&)$Rۚ§2)76'Mf9.(gG8ΏmdYM?mc"LY?;1,s\/ m{TEY;X{"iMidVp_\6tt˖U)i07pO{U W-Yx&or߼A E3%0`?GsP%NS'd(c|x? 9Hԛ}{!O٣\бu~iK.葼;jʅe|Mb5}0~ 'Yy-" bDu-(a]/m| NUMekNmh:A5xR]# 0 pi0o|υ st(>/ІFˋ=#)UhHJDcq9ƌ__ ;pFUdž.Tl O؞$٤)C>O/J8lAO[IT|y.: Ȑ4yLj9!)i!a4x&*l@mV-Sdzֺ]X4?Aޤ`$.07 Rb) \g*B8sڗ!BP]C v WaBk.fT:EYh٬m(1^='^=<01U9fƟQK7SE=> i4$g-J*ԑ1"QPk jL5%E G4BQLX%sY= aPP2aF]~X7GLWwAe } <,mh:bX3|,9Ey𓧘m !jIRu-X67L!R /̖aȨ:eI׀\4܀ے}^ԙZZ@{qe+mke}OUJՉ&d2pY7hl`UsηkˀLv/)N|g vR8[ZjW :G.[ #9ܴ+ a4l8^>Ǻ34˴Vn /㖯掓e;Yl6mg xϾPYh*(6X]:ШbG2c՗!%[-~|7Ϟ7`l1$3Q{X $0wD.ɕijԐ3UĖ&S&8Da$̟qY*ɨa215{īrJ`f.&U(1Q녳Fi#D=AR~Ot}U½Ȍod9fOǜ|]0/ ߖʯQ%UއGU,]dHt+[]<3kAPSC"œ ]y=s`׉@.ޣEpi ΁Pvu\NYv5Jϒ'BGK4Hx6KS¥)%r ;K{ŌP.2ey RoW}wݿptBYyh+A{eP]:@ۻ(zא9$!,5hB`6 .o?KcIJ+Z6܂ M{ϵ3rOhr~iIXg02J9^~1{ٚw+Ԏ:Fwa (-=v YS<[a\bLZ[ip̲%`;q̐Ɵ4/ayJX`Sb=|ju PGLU2O6R'w`S(r%P >uH-K8ؖ>`'f6+M1+ϝۧ 7.jw0& 詘mډ(EWlLf> {nl{n 4xTx;>D d (6jLu(UTȖh ].áhEA[1;]83sNY_0*f]i&ncg;8 =U2O %c>nC,9]g c3viG9Nk7¡2nq>\CZgs\n})wW8'.I,*@źd;8EBÏ> F mbh+6|eq(jZ Z}_grpcj-=p:Ӱ d-=bWFF0jr~&PPFzӼaWrhD{Rkb_jXUB9qʙTn-.|XIR J%ٕ4Ն\ ;L?"% ׮A01>g@ؓaͷuC3kjOWF_ ^LN)ه?|ߙkU?}eI8SI1qM)fs 0µ)M^;0A9"9F2Y`c,TNE+2d6zv. u涝j[7) kUG_&^} G e<2;[4<@֢N,f5o?bC37dlsIߚZatT*ʩJs.?Cr LP#lM/:,$sd79Pq0ztP^&"|Q_NV` |M(LOp*tM)|Pa#c0tp _iа'a<hオ 5 hm+t)eR kk IRېH kh`% HPO(ܧҫx`¦(_\ Exi;dhb<[  nlA62I5bD#ޗxܳV>tU > =tek4E LS1zu-Hc*ITX$bp  6\SXk N'w}?s9Z-gYB's=s"_ZRӂoE,p|SQ+:,tnBO$yjFګ|=n^<}lߒVnc;F~yvX|UW%po(:Wy9G`^̾DM_@Dy܂ ߣncRn}BsgJ:m\|)>@^~5ҪN{͠3cv#) 11f /jD8a;L#4!ϑY!{.ac$PrsȜ~D/Wy>E/`ckGo|Z.u>(`dYK7w{‡>so 8FN;)9>TlHųI!'TjM2T@t ]LiHg4eO"aCò_ *ϲ lKtTb~q4uͱN@$Ѩ) $/X 7_MpXEү~ǚ T&QA}2=ֽZɦF֦PStX]i"b(VbQs6)+oadf|1Pd!+qm+JQzV.S*$:&UWtwlX= hr4FLܪ\;m %).m~k֘ qNyd|j/ Azk=+|wco}T:cS`TAbɵ#9ms!lEevt'>Qmz;-zd].aKKNWg<^"rWB{pQ F#6f~ CLp`UvW̉uh|ŭH D7^N$k%ďA9VWp,Ak9\FpCPwxP]Jay˹ɑ7S"G1[;MPmT )ϽALb$K/_[Wp e6XMoDjFH9--]Q6eR;yoHGH a|EVE`3wOKkesx%ibQ$!}q h,IKFms޼a8zIrX:.( ?[ЄC.;z7m215 c5|^wOp̖п@}Θ ^2R~:1~jm'XƉl( >~-yI4H@/>+3f4y[P7K)RДnDWBE$T_`È0171'U&/wR E 0lYWᯔ3}g[2E~tU#jþ’zXhK}lFeֳ`As0bmt?¿j@+C(-&4*CRԇ%ij NX ʣvVs"3AW2*EF%<" ApMj'4Ƌ6)0~/gPO(IݤI8NRU+Bɰv$^AHF018OBEKD S}g~CU~+2Qt|ēYl7Ɯ;u7 "/ eNpKH6.;GZ霻4k@F*Qъ(XiȬ5'A׼Z:|= RJr<{4mn@:K(pP<\uY{jrW"Te7ER>#hKsDc/ -"E}}ybawAeܸY( S¶ W" 0 ^a܊g<T]{)Ek(}WH_P†,lE2pF-6=%.ͪi}qy,|9 y2BK}' 2UѣFYNZ-}y_( kJG4ĺ#͔o.Lp(?]飜{T˶вW6{ #γn2Hư6羿p` h9L8C^ t \;GlMft[em9]y̬H\ۚMRhW}e`Rw$ŎqFwBLz\Vi%Zs Va'uwcQG'8 E7v:+ Tk`+ FmS2׷=ʆة{K,ABhNT#N-WBѳ Oπ>J]e/F$בWG@]5E7{#4Vnʈ9Y~J_{ؿ%[Ukszˀ?h mOzNer܌ں}|Z@:?f Y8vkCαծ;eBs퉩$k$eI#-^LX% Gv$` um> u&&gis 6i1$ aWm 9z i3:'[MS"/c'E!M}o\0uiJyYx[3oW@e$kչv>&|[ kjgQM0ĩ־2N tt[p(?&J2A qږ*Y=,\2]CαPGMKu hKF{Dz FbfReW鼚y.Pqx Bʞ<^~dE)G,u $\4RmݍD15-o'ڪ&p@pKfdVGԊ}#҃8r",C(kL1#Y9"6Y4n_IN7\vUcIz1wiK6;L{ۺKSO2ePE @"gɘsßX4!ʃ*k,6Üe,xKar46KL0qRoPN*Œ=|0EWђʿ:V֩&}q? jMW,M;Yo]"Ȥkt?7-LPY虓r8͙H`z(I4U jWpr;z_?WzHe<[ 1(Lo{*A3Pʰ_)WFC[NjdW.Bfh0"E  ]J(˅VBMF)3뼾ԠYkdpWTI[TKJ`8$Vħ(%s7Z2nnrf2h{vd@-=>؞3~^pj .VG/COmC,Th1RE8NfO fe qnZd;M8t.H1V-;O5#9߄0 +[="Nٙ79:yz(/b}y, aQeǬ!l^{lqT)JYMms+-.mQ–gA2 &&Zy$i6'$ofyEVq=MbeA@Z;RUhl?e?ٵw;ЗŤӃK|у{,\{eeexы+/ o!ێ<_pckLF3xdp4tVqq// QSi| R]k Mi,6{uvLB<=v n1܃1(PN t#4Frֶ,Ce`ֿt8Uiǚ;cO|B$$|WăCB=[1%|JtB{1uwlaȁWT62mA7%{> zw0-|y`,gFeO{4LAi5xj*y"#*Mw7Qjޗe$uHcylQkPE HHoa%ھ&X/bȚ{IK?s 1#E[4 ƨٜI&=@vś%|]2m|njŬL?M(ڄ8q}qGɨWƆaiЮMevbD>A8L5N@q)7gnCtW\lT-qSi#)Wݾs0UbDU}WSvS a9{z4b{r_s+c=~,0p_XD ߤtkxhpw9#<]h+&Ij4q}̿@q'akwhPn4OO,4?ǀ` 5h@%x -'rڠU%j\iiCq 2Cvur.iv&{+~Ed0T){S)t5±\e) p;@@s @ھӶ >Tp=ErӅYKS]qQECݿrs VꙿFUxyK'Y w!!n%(-@]U8.4MN_ Τ.T_ƅwEm*|s t$:*2ZfMSi7.5/o)R *'A;ZƻNS4SP`'j5[#!ި1X68Cd5aiE=*Ki&y;(Pߚ/㍐^V5^&&xo=RقX9xZxSb?1~f7^_ $Oo i)X&RLt-+3\[5˄MeI!#]os,dža<)nCgUk[ ij9䅩:23o#C"4הTṳ̂6H &tFBԼ(gGWbHkgvƿJŎ}d]jahfs89~ᴄΈI d J+R|;LX7BYP}o]" V9M5WIK3Bsx:cS{Vڱ)vӑ\1/{-&^+uRez>VMhޥDU5l-c6,Cv=T: Q^6ooI{vA&ݎ j= 猪Ac@>{mnցشkBRQVT[W#IP̸^=iN7 ©IBޤա&ln2(9Ri]L'|ף 7m9] ogb#2t?A#/PW|tWbK۾c] 42DJ kZvk*fcC+#)?.8wu!_KYzoyMRxBe ߌ<\=}ԉgq-yaWkղyy$KB~sjLc†# (` b&}#MR͇+\\lA ,_Sq΋qʰ{:|Vɹ51 &>0I՚}7^Fe.]5>Ĉ;1njd4ѲKhhKݙ -H U˿ McKu+7,>r5q?aX*^)ˎ^Fe-F1wM-ΥKgWSCDp65V%"mЛAo6 PqQ^ _8ϨyXgʌۄd1ݍ"G؉T':N,23vn߾W_^{mmSڣd2Зx7 ϰ;=@{ " ҹ H ^dg:]҂-`;>mNKIq| V<4ǐ-B"-x g,lm) "Kzc&aX%mf~rh??v߹kG_C[[]X0r bI~|V@ۺutNck?:/rly.M5dz˸%L`3V-PMQ(މQPOocnuР@psr2hh;.FSEh~qA *TQ;*"ޙ]+ M$A& g jH3Zk>}B a(Uu)./y@He)ʣ6THmAKВVҖ܀؆ A_*5 O]7$ET:g8gu^r,m`W8w"Z2ՋF1&**Cshœ ږ$;j5羄g6mSx$>8lܭ3_ +Ǔp?ҫnA/0 lȧb9uN*8hF|k9S.c>F`04:UH[g-F&7k|PkPffn@+{%vTQ& χUq3XЮ~RL!$t!vWU4'ԸWD/^0'}hu:e^c;ΗLu49iH<na=D& )뉾MB| 0 JtL e}P i]M@ N&KW^״KK^䊙\CS:lCZy¼kp({m\z>E0b+qIjd͟*eSgr'*!%0%c-$MTZeg*kՊPp+Ks*:?߲Hj{WeO|c"k}ܙ;aϮ6=5jANBv|ey*B[ձ~2f"hfctf=^ 69'>ox9j]U?d0tXF 9.H.xpTqTy7nA)QKZ<<`Te"[J/sDۀay'ϹwSУ,A=M^}0 /+y!q[zjz/O3WswP48n̏S)V?oK^uihWUu+`G"nV0[4M&KCpGP$JJiI]ߖã8բ$ycϕS>| +M?$;BaA0I(Xxuۯ\ai@7zAj<{. y6Ax{!z$p"Pն%X0/L@_ I"ݠS  eT6Wuߩ)D{)w (#X rQ ۣdŬQk2 C&xZx02Tg%z&*tMGL7I)T"Z H@/KϿq9oKQuLَA L+{!٦huU{x}#&CʟržcreyөB;Ʉ~|gPM^\32|ꅱ"8'بatƒ$S`dۇ"p9=%GdL6H$r-Q3ApYtyxLbG_o+xAWl߸-BTZQ!"ag#¬8p %\e1=4lkQ݆,{)hkbŊ8ڄPV~Ν!p 16%h2MzCMʓN,7X'_lhˆ AM ɑ猽 s\/ݼO,\Z*b7$K1{\T9)Nڔ][ DsNZE>Ō9Y0.(@ b,3:ܷsS wr%alqα4&bX[ȡtlšl{sƇ)u @ +%^-xY\ YЋ9W;C0l_e$3jZAWXtk4 ۑEC&)T /#"J19ڵvhhHw],je:`YTGv^ߔAW4 Dz:!zNjz"kbj@{a I0!g>oukJ?M-w`S1$qZ]0m~E8:pl5+OP6gD^RQWP80S5WOɍ۹9 h"! R+3kI2 Ŋ^4k -aDe\NSH%bTn5M+C{`_!QsˁKXފ(7Ts@bH}-O˒-@>: ~ _1ksxv\ Ζqߟ2pv \fi&| I!8XK`+gHV0C^v.x'3֦%EqƮQX>`L=9Ѽ |-pE0I3=<% e _ xrSeSl@\ -3"^NQIvrZJ!6s¸WX4?6떦0݃U[X+D2^J n?#Գ [E p%կNmi5!ɄQ1 z湿CgbR4u4_)T<ֻI/pweh'Y6*Q(ĉ6Z^x }B;SlA>dj Ng@,!Z2uS@uN<"GAH gR|_;m~C/(^MJj3@C!g>a1f[SdTiA|rNKC16VOpPN=`P8,7xjth痍E_~M}XnUZ#Л[PF[2*F P`l-R̙IN3 O.r*3jZ[^T=J VoqzX솢5Y[Fp߹.ƶօpdf>x̀K!@~{#3/,́Wo`Ad5EMvpapla䮂Ԗ4;TKIa}ȶQ n[GN|- sh&'vđnkZ NH 2C=h|,437o2I7h^͈aͦX0Vmwz-P=^}}s}euݍKQͥGvpdTU{ mĝRrUN:j̦ѬxoeBrdpyVyMCܵ0\u9"*OݮZ7t Bk5sP3\ ˘>,@FE2L :p ~- I rc y:Dg~O%I ,G4n˸g+φO6e]ĶH#a?11=CɋM\_ WgP@ ,{| Au.ߐ0$}e3ՁsVv+>1k&PZo8v6gG<~{)k㩿@&; Gg?R'(dZw+E ڟ*F SvF/)+A_"[ 1.ACS|Upk~@g; +#Am0|kwyod b>pd>Jw|58wCD]FAۧ<oɃ6uBxcW'O'*Sd 2ۤt]Sv;wY<95F")*η9,FD.e `ʳʊJ078$!ץxQ,<}PKscΓ17/6ӷE]Vuz- w 06]f&k*pGyLĊb7G 9.>d-Z YO;Ky4͚SU ĥ6?=CW/`/\Qhuue\l hPnif#*.ȁW/o|ŤĹӎڋhfpBPثi,YHԺ$QkVVÅӫ$x ]į/ hg R$?yɠBKV]O0z*4rfUPEd3dՇQқ1kf3yk98CDj++P<Cy$psSy&v@TuV=$ݠoPK\VcqEKԙdnO;Ssy?pqrIgTiʙMJcL=(,We!Q%*|:24_~"q:dKlhIMY9s(i_I|PA, ^^i=O6AݦB0[?LEa$hfJ0hcVoĎLUӔBjgiT]|̮PӭV~G ͼ-۷+?K8q#/>:6\hD۰8*`d͆5p'd*@Gw]SwbujS0m@, rNʠI29oBQ$bU%⸖^xqϧeFECz01qXHiwQ"K6M;H8:~ X/@OT>¸] OAO+ܯX-a8>`s6cv/R `*lCk to!1}w-F_]/b`onBYnl[IH@55ž{%}.Эz!™|?uJ+z|`7A纻(!6[ dRa Kuz[~J] <62z3S=k }zRw ow`Ar? a⷇W,@&& }ldᔼe  D̟G] *=~g\$J ?6ˍ'ˈV\ʍʻ;٥9+-J `4 R[-$9)c؅5gVW8#c#ߘgc?abѫ |___ǿV=FXA[[a4.#UM; 8 t)Js^JByF**̎b"\˯TgڱONoIQlu!UUpբ Ԗ%t]ZiM`ǷdK! HYJ{ ?!Jcbƒ'߬g!祜FcI}O 20$ U|JFFNI W&]' u̎4#}Í*Wt`tkM ᷗҥ%$&c!y1X_PGh G?."Thb)Y{ t>As, qõaj-6Y=YuMuh(Lr D| ,gr7^e `r=F@ߜ̌TsuOUzS]`/ah%Г%dėp̮nLI%ՆMg$]y#ZY^{ e N_-7V)\dTA`%,xē7gG(PaPɻxE7H Eߥ )?Aa ^WR݂M)z'ܽOL&Q-Yhkq(>x+F1g{ <) 〙;!(4c%1 1+>CW^:}m]ˑ3 '3_iL { 鞭:aVN\ɪ˂=yD I10Oڠ@Ҕ[!s'vuv=\P9|T`EG1sG5M{8|ۃHp^w;S/xNk{EUR>pzԧi2!ax>e0#?S;""٥BIoJG\wS6+>WY-*WvI@xsBjY<>c4xd["ZZnpc$KY)KJ|ǣ-D-%IU'<%B>"g#(pМ&!ؕ(d$aî.BȨ}4kMTδAMnW="qJ;ubg]˖}>;#y;b4a25-U>5YM_FuO|֒T$WYV:opU1G C"S2[ET{1S86vq-מk6cXD:S҉[sYsehz+It maeHcf|쁏{dt"U'Ky6E}%W =LbƂ;쵼?8Jj>G4mZRZ2Ne򒢍X9^C!@nnw:ك D#Xo^ɿWcl&D bgsfn%EG<Oekj6 oaUj=rD@sU̿YLD~ԣ[,sqKj^,%m YU (dfW %t ;e`"*j>0#c{c`ĽYW%)ؕ ge~ ͉VO{hbw3nۗKt Tg(%@q;VN V1kYQ6^`"#w1Bq7e}|܂sDfc$lM}Vz_'hp42P"Չ|B0ZYBoߌ_'BhJe6yB ٖ:f /wbWPߎUY N!+LOR 2+Ojoeq2q6Fu3O$4z{ΡĖ,PsG9_I.(3bMΌx{rʬAzR0XJsSkj ~a5\ 8yvBl%